diff --git a/nsd-4.2.4.tar.gz b/nsd-4.2.4.tar.gz deleted file mode 100644 index bfa8352..0000000 --- a/nsd-4.2.4.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:9ebd6d766765631a56c0eb332eac26b310fa39f662e5582c8210488cf91ef27c -size 1148826 diff --git a/nsd-4.2.4.tar.gz.asc b/nsd-4.2.4.tar.gz.asc deleted file mode 100644 index ee40fda..0000000 --- a/nsd-4.2.4.tar.gz.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCAAdFiEEw+NWeI+tAXnYctCSuoEeYucZRWgFAl3vgE8ACgkQuoEeYucZ -RWjN1xAApOXcRNeQ9dPPHwZUwGCnzM/43K/t2LzAi3pHZNGrfTUSglwFvSTeCbnT -MW6rcTIyRoUkHiuDdlSIiPFgsGlLTj1klpxvp3Un+LVVdc621cj9G9JkYwMK+Fda -4WBkk56knYLxIPpPH1s7IWLsIYrm1pItlcfk8LOCxdSf+0zy9/FlNbtUWUqQg0pp -aREmagMI9gMPfutuUf5+g5kz1/0MGkgIMTQKqI3hBVjSVQDloPNsVXHbHMS/XRbe -DwFBAeiYPCA/ayUXF7MKCcnGWRYRYp5q5mHlOvRCldeQ0jKHcZdL3BU5Grz9+HWU -DV2QvfQl+MaD4SIe9ryaGF3yaZ8XSi4YzHSRi3bun+LihmArgLerQM53bpYUnlil -N6Jfz4KMy6kY3z3clZhxSh9qLlfyqZV7q5UahGnS7gLnUsTM7FXwmXaXWDh9SBYt -3O0M4u/ZN6jI48X0exntODq2AFmVvcAtaM2sqFNhIi9LFo6+g4c1X3vAx6SIUWAB -9y20Q9qLcRLeduleyi29ypmKff7pRQXl8PQX2wfBNVP2QTOedu897iL3TCodtZ31 -1hDIspMu+5tAPovv+AhYv09yDEhIfWjR36FqD9xL5Qep8AkHgAD5uX8CfZ8HPy3Y -4QqhyBLnb2rMQfsuUDQCI6qUtxmz8N1nPvWX/5cOxCV5L0fKLBM= -=6xb5 ------END PGP SIGNATURE----- diff --git a/nsd-4.3.0.tar.gz b/nsd-4.3.0.tar.gz new file mode 100644 index 0000000..ccd744c --- /dev/null +++ b/nsd-4.3.0.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7a007d655d30f1edd001206839107e651966e1e519d53ba2c036491044111e97 +size 1168198 diff --git a/nsd-4.3.0.tar.gz.asc b/nsd-4.3.0.tar.gz.asc new file mode 100644 index 0000000..b2d9fbb --- /dev/null +++ b/nsd-4.3.0.tar.gz.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCAAdFiEE7fqj8spObrBWga+On28cLX4EX40FAl5wn8AACgkQn28cLX4E +X40lyw//ZDpeuIZsiwbGlIHXvzVo87s2USrdyy+TtsPGOvRcvl89MNdbvWH6A5Me +p4dSyXAwT6y0pSqNndyo5S/0F3prr2ysvE0HueUfvtluY1aamdFZblh50FWZpC3W +Yb0X/GUWycRZdyQxhOg4CE32El/7+qijo7/VKUu6kSUim6+KUOPUMCPTzP01Fpjx +nr9AqLhGR/dBsa1mh04IrenHoiXtt4xPO/nz1zS5r0u/7oAq80/Kwgp0boqfcpJX +MKSQ+3xjaD/vEwt5IoOInd1b6O7s2D/AR9UVymloVZP7hJH7nBeVXRk2QqWhewQt +afi1mTLl4rt0ZL42Aotbiy+ub8a7qXh+fk60GLKo/0HsM9Y0YfCuKG+eBmuN2YFz +zAi5H6jS2yMOlOjB35I26BcwPcwSGVYkUXv9HMKzc8byAGPPNkigRhOWs/LD8wqx +Mi72xz4zXmdg5o4zJytRxZ2LVdsB2vDrXok78NqWPSFTufag38kj9pnSX/LHU8S3 +ZUAfI69IuFkBbIyrkviuUvsbYUDJ0pzAHUi/YT/0t8BefM6T9Cqp/h8f1295PO2x +NejcLNaII0uyrRUGf9k6jVCrOOKFrAHulNTlsxFeg1halbBhWnVqqXte/7yz9gdK +dpnjFfG6NdeGuRUkLyZ+EhaGxuO3XsCr8J2KeaHN2j61RrdEjNA= +=JHqI +-----END PGP SIGNATURE----- diff --git a/nsd.changes b/nsd.changes index 6859d11..a937d49 100644 --- a/nsd.changes +++ b/nsd.changes @@ -1,3 +1,65 @@ +------------------------------------------------------------------- +Tue Mar 17 20:52:34 UTC 2020 - Michael Ströder + +- New upstream release 4.3.0 + +FEATURES: +- Fix to use getrandom() for randomness, if available. +- Fix #56: Drop sparse TSIG signing support in NSD. + Sign every axfr packet with TSIG, according to the latest + draft-ietf-dnsop-rfc2845bis-06, Section 5.3.1. +- Merge pull request #59 from buddyns: add FreeBSD support + for conf key ip-transparent. +- Add feature to pin server processes to specific cpus. +- Add feature to pin IP addresses to selected server processes. +- Set process title to identify individual processes. +- Merge PR#22: minimise-any: prefer polular and not large RRset, + from Daisuke Higashi. +- Add support for SO_BINDTODEVICE on Linux. +- Add support for SO_SETFIB on FreeBSD. +- Add feature to drop queries with opcode UPDATE. + +BUG FIXES: +- Fix fname null check of fname in namedb_read_zonefile. +- Fix implicit cast of size in udb_radnode_array_grow. +- Fix ignore of return value of ssl_printf in remote.c. +- Fix unused check of fd in parent_handle_reload_command. +- Attempt to fix signedness of nscount lookup in ixfr query_process. +- Fix identical branches for ssl_print of errors in remote.c. +- Fix type cast bounds, signedness of opt_rdlen in edns_parse_record. +- Fix to separate header and data lines in parse_zone_list_file. +- Fix to define max number of EDNS records we are willing to + spend time on. +- Fix size of string len and capacity type cast in udbradtree. +- Fix to protect rrcount in tsig_find_rr from overflow. +- Annotate radix_find_prefix_node not reachable trail code. +- Fix to protect rrcount in packet_find_notify_serial from overflow. +- Fix to close socket on error in create_tcp_accept_sock. +- Fix to log on failure to chmod for socket for remote control. +- Fix to remove unneeded if in open of socket for remote control. +- Fix to restore input parameter on call failure in create_dirs. +- Please checker by terminating and initialising string read + by remote control. +- Fix to define upper bounds on rr counts read from untrusted packet + data. +- Separate acl_addr_match_range functions for ip4 and ip6, to + please checkers. +- Avoid unused variable warning in new match_range_v4 function. +- Fix whitespace in nsd.conf.sample.in, patch from Paul Wouters. +- use-systemd is ignored in nsd.conf, when NSD is compiled with + libsystemd it always signals readiness, if possible. +- Note that use-systemd is not necessary and ignored in man page. +- Fix unreachable code in ssl set options code. +- Fix bad shift in assertion code analyzer complaint. +- Fix responses for IXFR so that the authority section is not echoed + in the response. +- Merge PR#60: Minor portability fixes from michaelforney, with + avoid pointer arithmetic on void* and avoid unnecessary VLA. +- Fix that the retry wait does not exceed one day for zone transfers. + +CHANGES: +- Set FD_CLOEXEC on opened sockets. + ------------------------------------------------------------------- Thu Dec 12 15:50:13 UTC 2019 - Adam Majer diff --git a/nsd.spec b/nsd.spec index a0a22dd..de5fcf0 100644 --- a/nsd.spec +++ b/nsd.spec @@ -23,7 +23,7 @@ %define zonesdir %{configdir}/zones %define pidfile %{_rundir}/nsd/nsd.pid Name: nsd -Version: 4.2.4 +Version: 4.3.0 Release: 0 # Summary: An authoritative-only domain name server