Commit Graph

305 Commits

Author SHA256 Message Date
OBS User buildservice-autocommit
787a6987ff Updating link to change in openSUSE:Factory/bind revision 194
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=762e53966a54ca0bb04bbcf01bf8bd24
2023-04-22 19:59:07 +00:00
OBS User buildservice-autocommit
eb9a9ec36f Updating link to change in openSUSE:Factory/bind revision 193
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=7bc8e6997675ba7d19a2c93bc12cabb6
2023-03-17 16:02:26 +00:00
OBS User buildservice-autocommit
f533f093b7 Updating link to change in openSUSE:Factory/bind revision 192
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=5e1a9ea1a33ab3114347c7bd3dbe9bca
2023-02-17 15:44:01 +00:00
OBS User buildservice-autocommit
434a245765 Updating link to change in openSUSE:Factory/bind revision 191
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=8573380be7e7f2887d06bd1ddddfccf9
2023-01-26 12:57:06 +00:00
Jorik Cronenberg
41d4f93fff Accepting request 1055962 from home:thiagomacieira:branches:network
- Declare that named.service depends on network-online.target, otherwise named
  may start too early and thus fail (time out) when resolving some
  domains. This happens easily in containers.

OBS-URL: https://build.opensuse.org/request/show/1055962
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=366
2023-01-05 13:49:53 +00:00
OBS User buildservice-autocommit
19cd8cbb18 Updating link to change in openSUSE:Factory/bind revision 189
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=2ecd2eccaaa39eee6734fd9c04dfc9e4
2022-12-24 13:51:01 +00:00
OBS User buildservice-autocommit
9f456d305e Updating link to change in openSUSE:Factory/bind revision 188
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=4e74b41394010ac0fbd5e1e41a479352
2022-11-22 15:09:54 +00:00
OBS User buildservice-autocommit
730d928c4c Updating link to change in openSUSE:Factory/bind revision 187
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=28c940efa13669ca08dbcd40596e035c
2022-11-08 09:53:41 +00:00
Jorik Cronenberg
8eb032c2d5 Accepting request 1034274 from home:jcronenberg:branches:network
- Update to bind release 9.18.8
  New Features:
  * Support for parsing and validating the dohpath service
    parameter in SVCB records was added.
  * named now logs the supported cryptographic algorithms during
    startup and in the output of named -V.
  * The recursion not available and query (cache) '...' denied log
    messages were extended to include the name of the ACL that
    caused a given query to be denied.
  Bug Fixes:
  * An assertion failure was fixed in named that was caused by
    aborting the statistics channel connection while sending
    statistics data to the client.
  * Changing just the TSIG key names for primaries in catalog
    zones’ member zones was not effective. This has been fixed.
  Known Issues:
  * Upgrading from BIND 9.16.32, 9.18.6, or any older version may
    require a manual configuration change. The following
    configurations are affected:
    - type primary zones configured with dnssec-policy but without
      either allow-update or update-policy,
    - type secondary zones configured with dnssec-policy.
    In these cases please add inline-signing yes; to the individual
    zone configuration(s). Without applying this change, named will
    fail to start. For more details, see
    https://kb.isc.org/docs/dnssec-policy-requires-dynamic-dns-or-inline-signing
  * BIND 9.18 does not support dynamic update forwarding (see
    allow-update-forwarding) in conjuction with zone transfers over
    TLS (XoT).
  This obsoletes the following patch:
  * fix_documentation-Sphinx.patch

OBS-URL: https://build.opensuse.org/request/show/1034274
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=362
2022-11-07 15:48:12 +00:00
Jorik Cronenberg
f9c4ed7f87 Accepting request 1008578 from home:mcepl:branches:network
- Add fix_documentation-Sphinx.patch to fix building with the
  current Sphinx
  (https://gitlab.isc.org/isc-projects/bind9/-/issues/3572).
- Reapply bind-ldapdump-use-valid-host.patch

OBS-URL: https://build.opensuse.org/request/show/1008578
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=359
2022-10-06 23:52:09 +00:00
Jorik Cronenberg
7a18d2cf86 Accepting request 1005206 from home:jcronenberg:branches:network
- Update to bind release 9.18.7
  Security Fixes:
  * Previously, there was no limit to the number of database lookups
    performed while processing large delegations, which could be
    abused to severely impact the performance of named running as a
    recursive resolver. This has been fixed. (CVE-2022-2795)
  * When an HTTP connection was reused to request statistics from the
    stats channel, the content length of successive responses could
    grow in size past the end of the allocated buffer.
    This has been fixed. (CVE-2022-2881)
  * Memory leaks in code handling Diffie-Hellman (DH) keys were fixed
    that could be externally triggered, when using TKEY records in DH
    mode with OpenSSL 3.0.0 and later versions. (CVE-2022-2906)
  * named running as a resolver with the stale-answer-client-timeout
    option set to 0 could crash with an assertion failure, when there
    was a stale CNAME in the cache for the incoming query.
    This has been fixed. (CVE-2022-3080)
  * Memory leaks were fixed that could be externally triggered in the
    DNSSEC verification code for the EdDSA algorithm. (CVE-2022-38178)
  Feature Changes:
  * Response Rate Limiting (RRL) code now treats all QNAMEs that are
    subject to wildcard processing within a given zone as the same
    name, to prevent circumventing the limits enforced by RRL.
  * Zones using dnssec-policy now require dynamic DNS or
    inline-signing to be configured explicitly.
  * When reconfiguring dnssec-policy from using NSEC with an NSEC-only
    DNSKEY algorithm (e.g. RSASHA1) to a policy that uses NSEC3,
    BIND 9 no longer fails to sign the zone; instead, it keeps using
    NSEC until the offending DNSKEY records have been removed from the
    zone, then switches to using NSEC3.
  * A backward-compatible approach was implemented for encoding
    internationalized domain names (IDN) in dig and converting the
    domain to IDNA2008 form; if that fails, BIND tries an IDNA2003
    conversion.
  Bug Fixes:
  * A serve-stale bug was fixed, where BIND would try to return stale
    data from cache for lookups that received duplicate queries or
    queries that would be dropped. This bug resulted in premature
    SERVFAIL responses, and has now been resolved.
  This obsoletes the following patch:
  * bind-fix-mysql-bindings.patch
  [bsc#1203614, bsc#1203615, bsc#1203616, bsc#1203618, bsc#1203620]

OBS-URL: https://build.opensuse.org/request/show/1005206
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=357
2022-09-21 13:17:51 +00:00
b0d4a2d8fa Accepting request 998005 from home:jcronenberg:branches:network
- Fix typo in contrib/dlz/modules/{mysql,mysqldyn} that references
  LDAP_LIBS instead of MYSQL_LIBS.
  [bsc#1202149, bind.spec, bind-fix-mysql-bindings.patch]
- Update to bind release 9.18.6
  Bug Fixes:
  * When running as a validating resolver forwarding all queries
    to another resolver, named could crash with an assertion failure.
    These crashes occurred when the configured forwarder sent
    a broken DS response and named failed its attempts to find
    a proper one instead. This has been fixed.
  * Non-dynamic zones that inherit dnssec-policy from the view
    or options blocks were not marked as inline-signed
    and therefore never scheduled to be re-signed. This has been fixed.
  * The old max-zone-ttl zone option was meant to be superseded
    by the max-zone-ttl option in dnssec-policy; however,
    the latter option was not fully effective. This has been corrected:
    zones no longer load if they contain TTLs greater than the limit
    configured in dnssec-policy. For zones with both the old
    max-zone-ttl option and dnssec-policy configured,
    the old option is ignored, and a warning is generated.
  * rndc dumpdb -expired was fixed to include expired RRsets,
    even if stale-cache-enable is set to no and the cache-cleaning
    time window has passed.
  For a complete list of changes, see
  * Bind Release Notes
    https://downloads.isc.org/isc/bind9/9.18.6/doc/arm/html/notes.html
  * The CHANGES file in the source RPM
  [bind.spec bind-9.18.6.tar.xz bind-9.18.6.tar.xz.sha512.asc]

OBS-URL: https://build.opensuse.org/request/show/998005
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=355
2022-08-19 06:48:05 +00:00
Jorik Cronenberg
76349528f7 Accepting request 992780 from home:jcronenberg:branches:network
- When enabling query_logging by un-commenting an example in
  bind.conf, named attempts to create a file in /var/log which
  fails due to missing credentials. This also applies to the
  "dump-file" and the "statistics-file".
  This is solved by having systemd-tmpfiles create a subdirectory
  "/var/log/named" owned by named:named and changing the file
  paths accordingly:
  /var/log/named_querylog -> /var/log/named/querylog
  /var/log/named_dump.db -> /var/log/named/dump.db
  /var/log/named.stats -> /var/log/named/stats
  Also, in "named.service", the ReadWritePath was changed to
  include "/var/log/named" rather than just "var/log".
  [bsc#1200685, bind.conf, vendor-files/config/named.conf,
   vendor-files/system/named.service]

OBS-URL: https://build.opensuse.org/request/show/992780
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=353
2022-08-04 14:25:35 +00:00
Reinhard Max
30add1cedb Accepting request 992008 from home:jcronenberg:branches:network
- Add systemd drop-in directory for named service

OBS-URL: https://build.opensuse.org/request/show/992008
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=351
2022-08-01 11:54:00 +00:00
713ad10142 Accepting request 990505 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/990505
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=349
2022-07-21 09:48:29 +00:00
b842fbd70f Accepting request 982818 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/982818
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=347
2022-06-18 13:08:27 +00:00
ed2f268e4c OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=345 2022-06-04 23:56:02 +00:00
b36054bf8e Accepting request 978142 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/978142
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=344
2022-05-21 19:35:27 +00:00
ed00a571eb Accepting request 977055 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/977055
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=342
2022-05-16 08:30:17 +00:00
d16c91b060 Accepting request 977464 from home:marxin:branches:network
- Add upstream patch bind-prevent-buffer-overflow.patch.

OBS-URL: https://build.opensuse.org/request/show/977464
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=341
2022-05-16 08:27:30 +00:00
9fc32bb7e7 Accepting request 973839 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/973839
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=340
2022-05-06 07:52:29 +00:00
de343e57f9 Accepting request 966391 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/966391
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=339
2022-04-12 15:01:39 +00:00
a049546ee4 Accepting request 963527 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/963527
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=338
2022-03-31 09:30:02 +00:00
a6a277bcef bind-contrib-pthread.patch, named-bootconf.diff, bind-define-missing-threads.patch]
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=337
2022-02-24 16:24:59 +00:00
33b4dc7ca1 Accepting request 952940 from home:jmoellers:branches:network
Tested on Tumbleweed and SLE-15-SP4

OBS-URL: https://build.opensuse.org/request/show/952940
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=336
2022-02-23 12:08:26 +00:00
Josef Möllers
0036f07039 Accepting request 947995 from home:gmbr3:Active
- Add now working CONFIG parameter to sysusers generator

OBS-URL: https://build.opensuse.org/request/show/947995
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=335
2022-01-24 09:32:08 +00:00
02c9c898db Accepting request 947678 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/947678
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=334
2022-01-21 15:47:38 +00:00
2a94c20c41 Accepting request 940767 from home:jmoellers:branches:network
Test on SLES15-SP4 and TW successful

OBS-URL: https://build.opensuse.org/request/show/940767
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=333
2021-12-27 09:24:49 +00:00
Josef Möllers
dd9425ce8e Accepting request 935515 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/935515
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=332
2021-12-03 15:42:52 +00:00
bc2ee8dcfd Accepting request 930088 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/930088
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=331
2021-11-28 19:18:24 +00:00
9ad6dc50bb Accepting request 926001 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/926001
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=330
2021-10-20 13:06:21 +00:00
2145ed9993 Accepting request 924636 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/924636
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=329
2021-10-15 12:25:01 +00:00
Josef Möllers
1bfcffcd13 Version
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=328
2021-08-27 12:44:24 +00:00
8965708ce8 Accepting request 913006 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/913006
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=327
2021-08-27 11:49:05 +00:00
Josef Möllers
690c3ba2eb Accepting request 909186 from home:polslinux:branches:network
- Update to 9.16.19
  * A race condition could occur where two threads were
    competing for the same set of key file locks, leading to
    a deadlock. This has been fixed. [GL #2786]
  * create_keydata() created an invalid placeholder keydata
    record upon a refresh failure, which prevented the
    database of managed keys from subsequently being read
    back. This has been fixed. [GL #2686]
  * KASP support was extended with the "check DS" feature.
    Zones with "dnssec-policy" and "parental-agents"
    configured now check for DS presence and can perform
    automatic KSK rollovers. [GL #1126]
  * Rescheduling a setnsec3param() task when a zone failed
    to load on startup caused a hang on shutdown. This has
    been fixed. [GL #2791]
  * The configuration-checking code failed to account for
    the inheritance rules of the "dnssec-policy" option.
    This has been fixed. [GL #2780]
  * If nsupdate sends an SOA request and receives a REFUSED
    response, it now fails over to the next available
    server. [GL #2758]
  * For UDP messages larger than the path MTU, named now
    sends an empty response with the TC (TrunCated) bit set.
    In addition, setting the DF (Don't Fragment) flag on
    outgoing UDP sockets was re-enabled. [GL #2790]
  * Views with recursion disabled are now configured with a
    default cache size of 2 MB unless "max-cache-size" is
    explicitly set. This prevents cache RBT hash tables from
    being needlessly preallocated for such views. [GL #2777]
  * Change 5644 inadvertently introduced a deadlock: when
    locking the key file mutex for each zone structure in a
    different view, the "in-view" logic was not considered.
    This has been fixed. [GL #2783]
  * Increasing "max-cache-size" for a running named instance
    (using "rndc reconfig") did not cause the hash tables
    used by cache databases to be grown accordingly. This
    has been fixed. [GL #2770]
  * Signed, insecure delegation responses prepared by named
    either lacked the necessary NSEC records or contained
    duplicate NSEC records when both wildcard expansion and
    CNAME chaining were required to prepare the response.
    This has been fixed. [GL #2759]
  * A bug that caused the NSEC3 salt to be changed on every
    restart for zones using KASP has been fixed. [GL #2725]

OBS-URL: https://build.opensuse.org/request/show/909186
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=326
2021-07-29 13:39:41 +00:00
31ed332cd7 Accepting request 907456 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/907456
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=325
2021-07-21 11:50:51 +00:00
2d1a8b1c56 Accepting request 901768 from home:frispete:15.2
Hi,

here's an attempt to build the current bind with SLES/LEAP.
I tried to come up with something mode decent (replacement of 
sphinx.util.docutils.ReferenceRole), but run out of time.
With these admittedly ugly fixes, bind does build at least, 
including the ARM, but that is missing the clickable issues
in the version specific notes and being redirected to GitLab.

- Add patch bind-fix-build-with-older-sphinx.patch and sed fix
  in order to build with older distributions.

OBS-URL: https://build.opensuse.org/request/show/901768
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=324
2021-06-28 07:10:05 +00:00
712466db64 Accepting request 900882 from home:gmbr3:Active
- Add now working CONFIG parameter to sysusers generator

OBS-URL: https://build.opensuse.org/request/show/900882
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=323
2021-06-28 07:07:57 +00:00
114c6c58ca Accepting request 901419 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/901419
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=322
2021-06-23 09:39:20 +00:00
1aa8a9bb85 Accepting request 894731 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/894731
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=320
2021-05-24 12:18:49 +00:00
163f048d16 Accepting request 892098 from home:susnux:branches:network
SPEC file: Fixed outdated URL and use secured SourceURLs

OBS-URL: https://build.opensuse.org/request/show/892098
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=318
2021-05-11 21:04:47 +00:00
Lars Vogdt
3e40d2b6ff Accepting request 880720 from home:jengelh:branches:network
- Modernize specfile, and declare /bin/bash as required buildshell
  (use of {a,b} style expansion).

OBS-URL: https://build.opensuse.org/request/show/880720
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=316
2021-05-09 12:35:56 +00:00
Reinhard Max
1539ed7f3f Accepting request 891297 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/891297
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=315
2021-05-07 12:26:49 +00:00
649063bcfa Accepting request 887164 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/887164
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=313
2021-04-30 11:15:37 +00:00
de638e5cf5 Accepting request 878586 from home:mgerstner:branches:network
- pass PIE compiler and linker flags via environment variables to make
  /usr/bin/delv in bind-tools also position independent (bsc#1183453).
- drop pie_compile.diff: no longer needed, this patch is difficult to
  maintain, the environment variable approach is less error prone.

OBS-URL: https://build.opensuse.org/request/show/878586
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=311
2021-03-23 11:05:30 +00:00
fc3480a7ee Accepting request 874900 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/874900
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=310
2021-03-03 07:12:48 +00:00
Josef Möllers
04b4ed4df0 Accepting request 866630 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/866630
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=308
2021-01-26 08:58:48 +00:00
Josef Möllers
b585e7fb90 Accepting request 859291 from home:dirkmueller:branches:network
- update to 9.16.10:
  New Features:
  * NSEC3 support was added to KASP. A new option for dnssec-policy,
  nsec3param, can be used to set the desired NSEC3 parameters. NSEC3 salt
  collisions are automatically prevented during resalting. [GL #1620]
  * A new configuration option, stale-refresh-time, has been introduced. It allows
  a stale RRset to be served directly from cache for a period of time after a
  failed lookup, before a new attempt to refresh it is made. [GL #2066]
  Feature Changes:
  * The default value of max-recursion-queries was increased from 75 to 100.
  Since the queries sent towards root and TLD servers are now included in the
  count (as a result of the fix for CVE-2020-8616), max-recursion-queries has
  a higher chance of being exceeded by non-attack queries, which is the main
  reason for increasing its default value. [GL #2305]
  The default value of nocookie-udp-size was restored back to 4096 bytes. Since
  max-udp-size is the upper bound for nocookie-udp-size, this change relieves the
  operator from having to change nocookie-udp-size together with max-udp-size in
  order to increase the default EDNS buffer size limit. nocookie-udp-size can
  still be set to a value lower than max-udp-size, if desired. [GL #2250]
  Bug Fixes:
  Handling of missing DNS COOKIE responses over UDP was tightened by falling
  back to TCP. [GL #2275]
  The CNAME synthesized from a DNAME was incorrectly followed when the QTYPE was
  CNAME or ANY. [GL #2280]
  Building with native PKCS#11 support for AEP Keyper has been broken since BIND
  9.16.6. This has been fixed. [GL #2315]
  named could crash with an assertion failure if a TCP connection were closed
  while a request was still being processed. [GL #2227]
  named acting as a resolver could incorrectly treat signed zones with no DS
  record at the parent as bogus. Such zones should be treated as insecure. This

OBS-URL: https://build.opensuse.org/request/show/859291
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=306
2021-01-07 11:50:54 +00:00
d00771e830 Accepting request 848814 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/848814
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=304
2020-12-05 17:16:58 +00:00
Josef Möllers
303deef25b Accepting request 843167 from home:jmoellers:branches:network
Upgrade

OBS-URL: https://build.opensuse.org/request/show/843167
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=302
2020-10-21 13:48:54 +00:00