SHA256
1
0
forked from pool/bind
Commit Graph

258 Commits

Author SHA256 Message Date
163f048d16 Accepting request 892098 from home:susnux:branches:network
SPEC file: Fixed outdated URL and use secured SourceURLs

OBS-URL: https://build.opensuse.org/request/show/892098
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=318
2021-05-11 21:04:47 +00:00
Lars Vogdt
3e40d2b6ff Accepting request 880720 from home:jengelh:branches:network
- Modernize specfile, and declare /bin/bash as required buildshell
  (use of {a,b} style expansion).

OBS-URL: https://build.opensuse.org/request/show/880720
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=316
2021-05-09 12:35:56 +00:00
Reinhard Max
1539ed7f3f Accepting request 891297 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/891297
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=315
2021-05-07 12:26:49 +00:00
649063bcfa Accepting request 887164 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/887164
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=313
2021-04-30 11:15:37 +00:00
de638e5cf5 Accepting request 878586 from home:mgerstner:branches:network
- pass PIE compiler and linker flags via environment variables to make
  /usr/bin/delv in bind-tools also position independent (bsc#1183453).
- drop pie_compile.diff: no longer needed, this patch is difficult to
  maintain, the environment variable approach is less error prone.

OBS-URL: https://build.opensuse.org/request/show/878586
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=311
2021-03-23 11:05:30 +00:00
fc3480a7ee Accepting request 874900 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/874900
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=310
2021-03-03 07:12:48 +00:00
Josef Möllers
04b4ed4df0 Accepting request 866630 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/866630
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=308
2021-01-26 08:58:48 +00:00
Josef Möllers
b585e7fb90 Accepting request 859291 from home:dirkmueller:branches:network
- update to 9.16.10:
  New Features:
  * NSEC3 support was added to KASP. A new option for dnssec-policy,
  nsec3param, can be used to set the desired NSEC3 parameters. NSEC3 salt
  collisions are automatically prevented during resalting. [GL #1620]
  * A new configuration option, stale-refresh-time, has been introduced. It allows
  a stale RRset to be served directly from cache for a period of time after a
  failed lookup, before a new attempt to refresh it is made. [GL #2066]
  Feature Changes:
  * The default value of max-recursion-queries was increased from 75 to 100.
  Since the queries sent towards root and TLD servers are now included in the
  count (as a result of the fix for CVE-2020-8616), max-recursion-queries has
  a higher chance of being exceeded by non-attack queries, which is the main
  reason for increasing its default value. [GL #2305]
  The default value of nocookie-udp-size was restored back to 4096 bytes. Since
  max-udp-size is the upper bound for nocookie-udp-size, this change relieves the
  operator from having to change nocookie-udp-size together with max-udp-size in
  order to increase the default EDNS buffer size limit. nocookie-udp-size can
  still be set to a value lower than max-udp-size, if desired. [GL #2250]
  Bug Fixes:
  Handling of missing DNS COOKIE responses over UDP was tightened by falling
  back to TCP. [GL #2275]
  The CNAME synthesized from a DNAME was incorrectly followed when the QTYPE was
  CNAME or ANY. [GL #2280]
  Building with native PKCS#11 support for AEP Keyper has been broken since BIND
  9.16.6. This has been fixed. [GL #2315]
  named could crash with an assertion failure if a TCP connection were closed
  while a request was still being processed. [GL #2227]
  named acting as a resolver could incorrectly treat signed zones with no DS
  record at the parent as bogus. Such zones should be treated as insecure. This

OBS-URL: https://build.opensuse.org/request/show/859291
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=306
2021-01-07 11:50:54 +00:00
d00771e830 Accepting request 848814 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/848814
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=304
2020-12-05 17:16:58 +00:00
Josef Möllers
303deef25b Accepting request 843167 from home:jmoellers:branches:network
Upgrade

OBS-URL: https://build.opensuse.org/request/show/843167
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=302
2020-10-21 13:48:54 +00:00
Reinhard Max
c7de7e258a - Put libns into a separate subpackage to avoid file conflicts
in the libisc subpackage due to different sonums (bsc#1176092).

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=297
2020-09-04 14:42:49 +00:00
OBS User buildservice-autocommit
1d647cd766 Updating link to change in openSUSE:Factory/bind revision 156.0
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=90c94fa850d01fd39b0d70b750cd34f4
2020-09-01 07:49:42 +00:00
Reinhard Max
c61c37b69f Accepting request 830239 from home:dimstar:Factory
- Require /sbin/start_daemon: both init scripts, the one used in
  systemd context as well as legacy sysv, make use of start_daemon.

OBS-URL: https://build.opensuse.org/request/show/830239
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=295
2020-08-28 10:01:48 +00:00
Josef Möllers
cc91d0126a Accepting request 828392 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/828392
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=294
2020-08-21 08:19:08 +00:00
Josef Möllers
c10343c1a5 Accepting request 824686 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/824686
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=292
2020-08-17 06:19:40 +00:00
Josef Möllers
a7358e2599 Accepting request 822197 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/822197
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=290
2020-07-22 12:17:29 +00:00
Reinhard Max
13336b5b52 Accepting request 819259 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/819259
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=289
2020-07-21 07:32:24 +00:00
Josef Möllers
b1fcf64f8b Upgrade
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=286
2020-06-19 06:28:39 +00:00
Josef Möllers
8a582d1fe4 Upgrade
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=285
2020-06-18 08:10:17 +00:00
Josef Möllers
2f2463f9fc Upgrade
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=284
2020-06-18 07:53:27 +00:00
Josef Möllers
83408c75fa Upgrade
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=283
2020-06-18 07:41:56 +00:00
Josef Möllers
34efaf997b Upgrade
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=281
2020-06-18 06:51:39 +00:00
Josef Möllers
7b2635169f Accepting request 807719 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/807719
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=279
2020-05-20 12:55:33 +00:00
Josef Möllers
c79f35c371 Accepting request 787151 from home:kukuk:container
- Use sysusers.d to create named user
- Have only one package creating the user
- coreutils are not used in %post, remove Requires.
- Use systemd_ordering instead of hard requiring systemd

OBS-URL: https://build.opensuse.org/request/show/787151
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=269
2020-03-23 07:34:53 +00:00
Tomáš Chvátal
e58ea38bfe Accepting request 786770 from home:jmoellers:branches:network
Upgrade to 9.16.1

OBS-URL: https://build.opensuse.org/request/show/786770
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=267
2020-03-20 09:17:01 +00:00
Tomáš Chvátal
50814f9437 - Update download urls
- Do not enable geoip on old distros, the geoip db was shut down
  so we need to use geoip2 everywhere

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=265
2020-02-22 07:43:31 +00:00
Tomáš Chvátal
0264c27ba3 Accepting request 777947 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/777947
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=264
2020-02-22 07:32:01 +00:00
Tomáš Chvátal
e8ed0a004c Accepting request 761875 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/761875
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=262
2020-01-08 16:16:32 +00:00
Tomáš Chvátal
7782315a23 Accepting request 750049 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/750049
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=260
2019-11-22 08:28:25 +00:00
b29a01b4d4 Accepting request 746635 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/746635
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=259
2019-11-10 10:52:26 +00:00
Tomáš Chvátal
431b5383b2 Accepting request 714800 from home:mgerstner:branches:network
- removal of SuSEfirewall2 service from Factory, since SuSEfirewall2 has been
  replaced by firewalld, see [1].
  [1]: https://lists.opensuse.org/opensuse-factory/2019-01/msg00490.html

OBS-URL: https://build.opensuse.org/request/show/714800
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=257
2019-07-22 07:51:09 +00:00
Navin Kukreja
3f366a17af Accepting request 694778 from home:nkukreja:branches:network
- Add FIPS patch back into bind (bsc#1128220)
- File: bind-fix-fips.patch

OBS-URL: https://build.opensuse.org/request/show/694778
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=255
2019-04-16 10:45:29 +00:00
Ismail Dönmez
41d567bd7e Accepting request 637877 from home:cgiboudeaux:branches:network
- Update named.root. One of the root servers IP has changed.
- Install the LICENSE file.

OBS-URL: https://build.opensuse.org/request/show/637877
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=251
2018-09-25 08:40:30 +00:00
OBS User mrdocs
f183a6fcba Accepting request 621328 from home:kukuk:branches:network
- Add bind.conf and bind-chrootenv.conf to install the default
  files in /var/lib/named and create chroot environment on systems
  using transactional-updates [bsc#1100369] [FATE#325524].

OBS-URL: https://build.opensuse.org/request/show/621328
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=249
2018-07-19 05:20:17 +00:00
OBS User mrdocs
2b99721cd9 Accepting request 618489 from home:kukuk:branches:network
- Cleanup pre/post install: remove all old code which was needed to
  update to SLES8.

OBS-URL: https://build.opensuse.org/request/show/618489
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=247
2018-06-27 04:27:15 +00:00
Navin Kukreja
6e77e065be Accepting request 614182 from home:nkukreja:branches:network
- Fix the hostname in ldapdump to be valid (bsc#965748)

OBS-URL: https://build.opensuse.org/request/show/614182
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=242
2018-06-05 09:30:33 +00:00
Navin Kukreja
34d201c2e7 Accepting request 611353 from home:scabrero:branches:network
- Add bug-4697-Restore-workaround-for-Microsoft-Windows-T.patch
  Fixes dynamic DNS updates against samba and Microsoft DNS servers
  (bsc#1094236).

OBS-URL: https://build.opensuse.org/request/show/611353
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=240
2018-05-23 09:09:10 +00:00
Navin Kukreja
ccaf6117d3 Accepting request 610097 from home:nkukreja:branches:network
- Move chroot related files from bind to bind-chrootenv 
  (bsc#1093338)

OBS-URL: https://build.opensuse.org/request/show/610097
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=239
2018-05-17 14:45:41 +00:00
Navin Kukreja
69299c3f09 Accepting request 609105 from home:nkukreja:branches:network
- Remove rndc.key generation from bind.spec file because bind
  should create it on first boot (bsc#1092283)
- Add misisng rndc.key check and generation code is lwresd.init
  script

OBS-URL: https://build.opensuse.org/request/show/609105
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=238
2018-05-16 10:46:10 +00:00
862ae2408a Accepting request 580513 from home:rudi_m:branches:network
- build with --enable-filter-aaaa to make it possible to use
  config option "filter-aaaa-on-v4 yes". Useful to workaround
  broken websites like netflix which block traffic from certain
  IPv6 tunnel providers.

OBS-URL: https://build.opensuse.org/request/show/580513
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=234
2018-02-27 10:12:33 +00:00
709c0c9ee2 Accepting request 577255 from home:bmwiedemann:branches:network
Add /dev/urandom to chroot env 
note: it is not world writable to make our rpmlint security checker happy - and it is not required anyway

without this, named start shows warnings in journal:
Feb 16 13:28:35 testleap named[1514]: could not open entropy source /dev/urandom: file not found
Feb 16 13:28:35 testleap named[1514]: using pre-chroot entropy source /dev/urandom

OBS-URL: https://build.opensuse.org/request/show/577255
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=232
2018-02-16 14:01:14 +00:00
Navin Kukreja
c27658fca1 Accepting request 574119 from home:nkukreja:branches:network
- Implement systemd init scripts for bind and lwresd (fate#323155)

OBS-URL: https://build.opensuse.org/request/show/574119
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=230
2018-02-08 13:15:18 +00:00
Navin Kukreja
41f90b8125 Accepting request 568769 from home:nkukreja:branches:network
- Apply bind-CVE-2017-3145.patch to fix CVE-2017-3145 (bsc#1076118)

OBS-URL: https://build.opensuse.org/request/show/568769
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=228
2018-01-23 22:28:59 +00:00
Ismail Dönmez
3dc2357a41 Accepting request 554799 from home:vitezslav_cizek:branches:network
- Use getent when adding user/group
- update changelog to mention removed options

  * Remove no longer recognized --enable-rrl

OBS-URL: https://build.opensuse.org/request/show/554799
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=226
2017-12-07 10:37:08 +00:00
e04eec6142 - license changed to MPL-2.0 according to legal.
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=225
2017-11-25 15:31:35 +00:00
b264302d00 Accepting request 545259 from home:scarabeus_iv:branches:network
- Add back init scripts, systemd units aren't ready yet

- Add python3-bind subpackage to allow python bind interactions

- Sync configure options with RH package and remove unused ones
  * Enable python3
  * Enable gssapi
  * Enable dnssec scripts

- Drop idnkit from the build, the bind uses libidn since 2007 to run
  all the resolutions in dig/etc. bsc#1030306
- Add patch to make sure we build against system idn:
  * bind-99-libidn.patch
- Refresh patch:
  * pie_compile.diff
- Remove patches that are unused due to above:
  * idnkit-powerpc-ltconfig.patch
  * runidn.diff

- drop bind-openssl11.patch (merged upstream)

- Remove systemd conditionals as we are not building on sle11 anyway
- Force the systemd to be base for the initscript deployment

- Bump up version of most of the libraries
- Rename the subpackages to match the version updates
- Add macros for easier handling of the library package names
- Drop more unneeded patches
  * dns_dynamic_db.patch (upstream)

OBS-URL: https://build.opensuse.org/request/show/545259
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=224
2017-11-24 16:29:49 +00:00
6c11f8d877 Accepting request 544658 from home:RBrownSUSE:branches:network
Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)

OBS-URL: https://build.opensuse.org/request/show/544658
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=223
2017-11-24 10:22:50 +00:00
fc48f6ba17 Accepting request 543879 from home:pluskalm:branches:network
- Use python3 by default (fate#323526)

OBS-URL: https://build.opensuse.org/request/show/543879
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=221
2017-11-21 09:43:45 +00:00
OBS User mrdocs
efc0e572f3 Accepting request 523293 from home:msmeissn:branches:network
- bind-openssl11.patch: add a patch for enabling
  openssl 1.1 support (builds for 1.0 and 1.1 openssl).
  (bsc#1042635)

OBS-URL: https://build.opensuse.org/request/show/523293
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=219
2017-09-14 01:12:46 +00:00
dcab876062 OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=217 2017-09-07 12:06:06 +00:00
7e6301a923 Accepting request 520246 from home:j-engel:branches:network
- Enable JSON statistics

OBS-URL: https://build.opensuse.org/request/show/520246
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=216
2017-09-07 12:02:08 +00:00
OBS User mrdocs
4215a9d83e Accepting request 507735 from home:dimstar:Factory
- Run systemctl daemon-reload even when this is not build with
  systemd support: if installing bind on a systemd service and not
  reloading systemd daemon, then the service 'named' is not known
  right after package installation, causing confusion.

OBS-URL: https://build.opensuse.org/request/show/507735
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=212
2017-07-03 22:11:50 +00:00
43448a770a Accepting request 507232 from home:simotek:branches:network
- Added bind-CVE-2017-3142-and-3143.patch to fix a security issue
  where an attacker with the ability to send and receive messages
  to an authoritative DNS server was able to circumvent TSIG
  authentication of AXFR requests. A server that relies solely on
  TSIG keys for protection with no other ACL protection could be
  manipulated into (1) providing an AXFR of a zone to an
  unauthorized recipient and (2) accepting bogus Notify packets.
  [bsc#1046554, CVE-2017-3142, bsc#1046555, CVE-2017-3143]

OBS-URL: https://build.opensuse.org/request/show/507232
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=211
2017-06-30 10:58:48 +00:00
7b1425a23f Accepting request 496935 from home:dimstar:Factory
a- Fix named init script to dynamically find the location of the
   openssl engines (boo#1040027).

OBS-URL: https://build.opensuse.org/request/show/496935
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=209
2017-05-20 15:34:20 +00:00
4e8c935dd7 Accepting request 481339 from home:kukuk:branches:network
- Add with_systemd define with default off, since we still use init
  scripts and no systemd units.

OBS-URL: https://build.opensuse.org/request/show/481339
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=207
2017-03-23 16:11:03 +00:00
44c7103fc2 Accepting request 458921 from home:kukuk:branches:network
- Don't require and call insserv if we use systemd

OBS-URL: https://build.opensuse.org/request/show/458921
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=205
2017-02-21 10:39:18 +00:00
Navin Kukreja
9e49836a48 Accepting request 457420 from home:nkukreja:branches:network
- Fix assertion failure or a NULL pointer read for configurations using both DNS64 and RPZ
  * CVE-2017-3135, bsc#1024130
  * bind-CVE-2017-3135.patch

OBS-URL: https://build.opensuse.org/request/show/457420
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=203
2017-02-15 13:26:45 +00:00
c6ec97ecb6 Accepting request 449784 from home:simotek:branches:network
Fix bsc#1018699 by taking latest update in series 9.11 needs a little more work

OBS-URL: https://build.opensuse.org/request/show/449784
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=200
2017-01-12 12:21:22 +00:00
318666062f Accepting request 438189 from home:psimons:branches:network
Apply cve-2016-8864.patch to fix CVE-2016-8864 (bsc#1007829).

OBS-URL: https://build.opensuse.org/request/show/438189
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=198
2016-11-02 13:30:34 +00:00
Ismail Dönmez
7af14e49dd Accepting request 430610 from home:psimons:branches:network
Security update to fix CVE-2016-2776 (bsc#1000362).

OBS-URL: https://build.opensuse.org/request/show/430610
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=196
2016-09-27 18:38:49 +00:00
Reinhard Max
8b99b04f2a - Remove the start/stop dependency of named and lwresd on remote-fs
to break a service dependency cycle (bsc#947483, bsc#963971).
- Make /var/lib/named owned by the named user (bsc#908850,
  bsc#875691).
- Call systemd service macros with the full service name.
- Security update 9.10.3-P4:

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=194
2016-06-16 12:00:45 +00:00
Rusmir Duško
2e4b7daa78 Accepting request 389954 from home:lnussel:branches:network
- remove BuildRequire libcap. That is only a legacy library, not
  actually used for building. libcap-devel pulls in the right one.

OBS-URL: https://build.opensuse.org/request/show/389954
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=192
2016-04-15 07:56:29 +00:00
Reinhard Max
abbe73be65 - Security update 9.10.3-P3 fixes two assertion failures that can
lead to remote DoS:
  * CVE-2016-1285, bsc#970072
  * CVE-2016-1286, bsc#970073

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=189
2016-03-11 13:55:29 +00:00
0f06af6f9d Accepting request 361463 from home:bmwiedemann:branches:network
- drop a changing timestamp making build reproducible

OBS-URL: https://build.opensuse.org/request/show/361463
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=187
2016-02-26 07:55:47 +00:00
Lars Müller
fd2b586269 Sligthly enhance the last commmit
- \ at the last option line allows us to keep the full history
- a tab is no a space

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=186
2016-02-12 21:48:50 +00:00
Lars Müller
9508d45935 Accepting request 359100 from home:elvigia:branches:network
- Build with --with-randomdev=/dev/urandom otherwise 
  libisc will use /dev/random to gather entropy and that might
  block, short read etc..

OBS-URL: https://build.opensuse.org/request/show/359100
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=185
2016-02-12 19:11:31 +00:00
Reinhard Max
c7dc2ebf4f - Security update 9.10.3-P3:
* Specific APL data could trigger an INSIST (CVE-2015-8704,
    bsc#962189).
  * Certain errors that could be encountered when printing out or
    logging an OPT record containing a CLIENT-SUBNET option could
    be mishandled, resulting in an assertion failure
    (CVE-2015-8705, bsc#962190).
  * Authoritative servers that were marked as bogus (e.g.
    blackholed in configuration or with invalid addresses) were
    being queried anyway.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=183
2016-01-20 11:04:34 +00:00
Reinhard Max
5f956be5fc - Update to version 9.10.3-P2 to fix a remote denial of service by
misparsing incoming responses (CVE-2015-8000, bsc#958861).

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=180
2015-12-21 17:12:31 +00:00
Reinhard Max
ee28860376 Accepting request 336332 from home:jengelh:branches:network
- Avoid double %setup, it confuses some versions of quilt.
- Summary/description update

OBS-URL: https://build.opensuse.org/request/show/336332
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=178
2015-10-05 07:46:26 +00:00
Lars Müller
f17cebd7c5 Accepting request 332971 from home:msmeissn:branches:network
- Update to version 9.10.2-P4
  * An incorrect boundary boundary check in the OPENPGPKEY
    rdatatype could trigger an assertion failure.
    (CVE-2015-5986) [RT #40286] (bsc#944107)
  * A buffer accounting error could trigger an
    assertion failure when parsing certain malformed 
    DNSSEC keys. (CVE-2015-5722) [RT #40212] (bsc#944066)

OBS-URL: https://build.opensuse.org/request/show/332971
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=176
2015-09-22 20:15:47 +00:00
Lars Müller
f94eebf621 - Update to version 9.10.2-P3
Security Fixes
  * A specially crafted query could trigger an assertion failure in message.c.
    This flaw was discovered by Jonathan Foote, and is disclosed in
    CVE-2015-5477. [RT #39795]
  * On servers configured to perform DNSSEC validation, an assertion failure
    could be triggered on answers from a specially configured server.
    This flaw was discovered by Breno Silveira Soares, and is disclosed
    in CVE-2015-4620. [RT #39795]
  Bug Fixes
  * Asynchronous zone loads were not handled correctly when the zone load was
    already in progress; this could trigger a crash in zt.c. [RT #37573]
  * Several bugs have been fixed in the RPZ implementation:
    + Policy zones that did not specifically require recursion could be treated
      as if they did; consequently, setting qname-wait-recurse no; was
      sometimes ineffective. This has been corrected. In most configurations,
      behavioral changes due to this fix will not be noticeable. [RT #39229]
    + The server could crash if policy zones were updated (e.g. via
      rndc reload or an incoming zone transfer) while RPZ processing
      was still ongoing for an active query. [RT #39415]
    + On servers with one or more policy zones configured as slaves, if a
      policy zone updated during regular operation (rather than at startup)
      using a full zone reload, such as via AXFR, a bug could allow the RPZ
      summary data to fall out of sync, potentially leading to an assertion
      failure in rpz.c when further incremental updates were made to the zone,
      such as via IXFR. [RT #39567]
    + The server could match a shorter prefix than what was
      available in CLIENT-IP policy triggers, and so, an unexpected
      action could be taken. This has been corrected. [RT #39481]
    + The server could crash if a reload of an RPZ zone was initiated while

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=174
2015-07-29 19:36:46 +00:00
Lars Müller
5693887a0c - Update to version 9.10.2-P2
- An uninitialized value in validator.c could result in an assertion failure.
    (CVE-2015-4620) [RT #39795]
- Update to version 9.10.2-P1
  - Include client-ip rules when logging the number of RPZ rules of each type.
    [RT #39670]
  - Addressed further problems with reloading RPZ zones. [RT #39649]
  - Addressed a regression introduced in change #4121. [RT #39611]
  - The server could match a shorter prefix than what was available in
    CLIENT-IP policy triggers, and so, an unexpected action could be taken.
    This has been corrected. [RT #39481]
  - On servers with one or more policy zones configured as slaves, if a policy
    zone updated during regular operation (rather than at startup) using a full
    zone reload, such as via AXFR, a bug could allow the RPZ summary data to
    fall out of sync, potentially leading to an assertion failure in rpz.c when
    further incremental updates were made to the zone, such as via IXFR.
    [RT #39567]
  - A bug in RPZ could cause the server to crash if policy zones were updated
    while recursion was pending for RPZ processing of an active query.
    [RT #39415]
  - Fix a bug in RPZ that could cause some policy zones that did not
    specifically require recursion to be treated as if they did; consequently,
    setting qname-wait-recurse no; was sometimes ineffective. [RT #39229]
  - Asynchronous zone loads were not handled correctly when the zone load was
    already in progress; this could trigger a crash in zt.c. [RT #37573]
  - Fix an out-of-bounds read in RPZ code. If the read succeeded, it doesn't
    result in a bug during operation. If the read failed, named could segfault.
    [RT #38559]

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=172
2015-07-10 20:54:40 +00:00
755db9e738 Accepting request 311393 from home:guohouzuo:freeipa
Fix inappropriate use of /var/lib/named for locating dynamic-DB plugins.
Dynamic-DB plugins are now loaded from %{_libexecdir}/bind, consistent with openSUSE packaging guideline.
Install additional header files which are helpful to the development of dynamic-DB plugins.

Please note that - the so-far only implementation of dyanmic-DB plugin does not support running in chroot environment very well, there is great performance impact in doing so.

OBS-URL: https://build.opensuse.org/request/show/311393
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=169
2015-06-18 12:30:16 +00:00
Lars Müller
1ea9273bb0 This change set makes bind build again for SLE 11 too.
- Depend on systemd macros and sysvinit on post-12.3 only.
- Create empty lwresd.conf at build time.
- Reduce file list pre-13.1.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=167
2015-05-08 18:11:21 +00:00
Lars Müller
44ffc351bb - Update to version 9.10.2
- Handle timeout in legacy system test. [RT #38573]
  - dns_rdata_freestruct could be called on a uninitialised structure when
    handling a error. [RT #38568]
  - Addressed valgrind warnings. [RT #38549]
  - UDP dispatches could use the wrong pseudorandom
    number generator context. [RT #38578]
  - Fixed several small bugs in automatic trust anchor management, including a
    memory leak and a possible loss of key state information. [RT #38458]
  - 'dnssec-dsfromkey -T 0' failed to add ttl field. [RT #38565]
  - Revoking a managed trust anchor and supplying an untrusted replacement
    could cause named to crash with an assertion failure.
    (CVE-2015-1349) [RT #38344]
  - Fix a leak of query fetchlock. [RT #38454]
  - Fix a leak of pthread_mutexattr_t. [RT #38454]
  - RPZ could send spurious SERVFAILs in response
    to duplicate queries. [RT #38510]
  - CDS and CDNSKEY had the wrong attributes. [RT #38491]
  - adb hash table was not being grown. [RT #38470]
- Update bind.keyring
- Update baselibs.conf due to updates to libdns160 and libisc148

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=166
2015-05-08 15:44:01 +00:00
Lars Müller
fa2687cc7a Accepting request 305950 from home:guohouzuo:freeipa
- Enable export libraries to support plugin development.
  Install DNSSEC root key.
  Expose new interface for developing dynamic zone database.
  + dns_dynamic_db.patch

OBS-URL: https://build.opensuse.org/request/show/305950
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=165
2015-05-08 14:24:45 +00:00
a72d9724b3 Accepting request 285468 from home:k0da:branches:network
- PowerPC can build shared libraries for sure.
  idnkit-powerpc-ltconfig.patch

OBS-URL: https://build.opensuse.org/request/show/285468
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=163
2015-02-11 12:29:20 +00:00
Andrey Karepin
4d1f101c72 added mistakenly deleted row (Request 266520)
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=161
2015-01-11 18:19:25 +00:00
Andrey Karepin
43ba3368ef Accepting request 266520 from home:jengelh:branches:network
- Explicitly BuildRequire systemd-rpm-macros since it is used
  for lwresd %post etc. Then drop pre-12.x material.
  Remove configure.in.diff2.

OBS-URL: https://build.opensuse.org/request/show/266520
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=160
2015-01-11 16:14:25 +00:00
Lars Müller
70eef698ee Accepting request 264794 from home:jengelh:branches:network
- Corrections to baselibs.conf
Just merge my changes properly already.

OBS-URL: https://build.opensuse.org/request/show/264794
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=157
2014-12-11 14:46:49 +00:00
Lars Müller
24da4f54fa Accepting request 264596 from home:lmuelle:bind
- Update to version 9.10.1-P1
  - A flaw in delegation handling could be exploited to put named into an
    infinite loop.  This has been addressed by placing limits on the number of
    levels of recursion named will allow (default 7), and the number of
    iterative queries that it will send (default 50) before terminating a
    recursive query (CVE-2014-8500); (bnc#908994).
    The recursion depth limit is configured via the "max-recursion-depth"
    option, and the query limit via the "max-recursion-queries" option.
    [RT #37580]
  - When geoip-directory was reconfigured during named run-time, the
    previously loaded GeoIP data could remain, potentially causing wrong ACLs
    to be used or wrong results to be served based on geolocation
    (CVE-2014-8680). [RT #37720]; (bnc#908995).
  - Lookups in GeoIP databases that were not loaded could cause an assertion
    failure (CVE-2014-8680). [RT #37679]; (bnc#908995).
  - The caching of GeoIP lookups did not always handle address families
    correctly, potentially resulting in an assertion failure (CVE-2014-8680).
    [RT #37672]; (bnc#908995).

OBS-URL: https://build.opensuse.org/request/show/264596
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=156
2014-12-09 22:47:11 +00:00
c38019450e Accepting request 264325 from home:lmuelle:bind
Merge request 264305:

- Convert some hard PreReq to leaner Requires(pre).
- Typograhical and orthographic fixes to description texts.

Changes already present with request 264243:

- Fix bashisms in the createNamedConfInclude script.
- Post scripts: remove '-e' option of 'echo' that may be unsupported
  in some POSIX-compliant shells.

- Add openssl engines to the lwresd chroot.
- Add /etc/lwresd.conf with attribute ghost to the list of files.
- Add /run/lwresd to the list of files of the lwresd package.
- Shift /run/named from the chroot sub to the main bind package.
- Drop /proc from the chroot as multi CPU systems work fine even without it.

OBS-URL: https://build.opensuse.org/request/show/264325
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=155
2014-12-08 08:18:17 +00:00
932f848950 Accepting request 264083 from home:lmuelle:bind
- Add a versioned dependency when obsoleting packages.

- Remove superfluous obsoletes *-64bit in the ifarch ppc64 case; (bnc#437293).

- Fix gssapi_krb configure time header detection.

- Update root zone (dated Nov 5, 2014).

- Update to version 9.10.1
  - This release addresses the security flaws described in CVE-2014-3214 and
     CVE-2014-3859.
- Update to version 9.10.0
- Update to version 9.9.6

  Cf the bind changes file for all the details of 9.9.6 till 9.10.1.

- Remove merged rpz2+rl-9.9.5.patch and obsoleted rpz2+rl-9.9.5.patch
- Update baselibs.conf (added libirs and library interface version updates).

OBS-URL: https://build.opensuse.org/request/show/264083
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=153
2014-12-05 10:12:05 +00:00
Lars Müller
e179acbc40 Accepting request 261547 from home:dimstar:gpg2
OBS-URL: https://build.opensuse.org/request/show/261547
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=152
2014-11-14 10:36:34 +00:00
Reinhard Max
dab82c1e27 Accepting request 253555 from home:jengelh:branches:network
the IDN parts are totally optional

OBS-URL: https://build.opensuse.org/request/show/253555
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=151
2014-10-16 14:25:14 +00:00
Andrey Karepin
48ca52dcbe Accepting request 248172 from home:WernerFink:branches:network
- Require systemd-rpm-macros at build

OBS-URL: https://build.opensuse.org/request/show/248172
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=149
2014-09-12 05:49:00 +00:00
Reinhard Max
c0a72d4f0b Accepting request 248035 from home:WernerFink:branches:network
- Use the systemd service macros to make sure init scripts are
  registered properly (bnc#894627)

OBS-URL: https://build.opensuse.org/request/show/248035
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=148
2014-09-08 14:06:56 +00:00
ed559646e6 Accepting request 243329 from home:lmuelle:branches:network
- Package dnssec-checkds and dnssec-coverage binaries and man pages only on
  post-11.1 systems.

- Update to version 9.9.5P1
  Various bugfixes and some feature fixes. (see CHANGES files)
  Security and maintenance issues:
  - [bug] Don't call qsort with a null pointer. [RT #35968]
  - [bug] Disable GCC 4.9 "delete null pointer check". [RT #35968]
  - [port] linux: libcap support: declare curval at start of block. [RT #35387]
- Update to version 9.9.5
  Various bugfixes and some feature fixes. (see CHANGES files)
- Updated to current rpz patch from·http://ss.vix.su/~vjs/rrlrpz.html
  - rpz2-9.9.4.patch
  + rpz2+rl-9.9.5.patch

OBS-URL: https://build.opensuse.org/request/show/243329
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=144
2014-08-01 11:43:42 +00:00
b25ceb6024 Accepting request 235320 from home:elvigia:branches:network
- Build with LFS_CFLAGS in 32 bit systems.

OBS-URL: https://build.opensuse.org/request/show/235320
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=141
2014-06-01 10:06:10 +00:00
Reinhard Max
9927c8db29 Accepting request 233009 from home:oertel:branches:network
- use %_rundir macro

OBS-URL: https://build.opensuse.org/request/show/233009
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=138
2014-05-08 09:51:15 +00:00
Reinhard Max
f40daf517b - Add the sdb-ldap backend module (fate#313216).
- Details can be found here:
  * http://bind9-ldap.bayour.com/
  * http://bind9-ldap.bayour.com/dnszonehowto.html

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=136
2014-01-24 10:15:48 +00:00
Reinhard Max
2280b862ef - Update to version 9.9.4P2
* Fixes named crash when handling malformed NSEC3-signed zones
    (CVE-2014-0591, bnc#858639)
  * Obsoletes workaround-compile-problem.diff
- Replace rpz2+rl-9.9.3-P1.patch by rpz2-9.9.4.patch, rl is now
  supported upstream (--enable-rrl).

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=134
2014-01-21 17:09:17 +00:00
Reinhard Max
ef9b332868 - Improve pie_compile.diff (bnc#828874).
- dnssec-checkds and dnssec-coverage need python-base.
- disable rpath in libtool.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=127
2013-08-06 13:06:41 +00:00
Reinhard Max
2e7cad6b7d dnssec-checkds and dnssec-coverage need python-base for building.
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=126
2013-08-06 09:11:23 +00:00
Reinhard Max
28ef07b698 - Update to 9.9.3P2 fixes CVE-2013-4854, bnc#831899.
* Incorrect bounds checking on private type 'keydata' can lead
    to a remotely triggerable REQUIRE failure.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=125
2013-08-05 14:51:21 +00:00
Reinhard Max
8e89b870e6 - Remove non-working apparmor profiles (bnc#740327).
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=123
2013-07-24 15:38:10 +00:00
918e706647 - the README file is not a directory, drop the dir attribute
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=121
2013-07-17 12:09:28 +00:00
67378e3874 - moved dnssec-* helpers to bind-utils package. bnc#813911
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=119
2013-06-27 09:27:34 +00:00
7f803cee73 - Updated to current rate limiting + rpz patch from
http://ss.vix.su/~vjs/rrlrpz.html

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=118
2013-06-26 12:27:48 +00:00
8591e27de2 - Updated to 9.9.3-P1
Various bugfixes and some feature fixes. (see CHANGES files)
  Security and maintenance issues: 
  -	[security]	Caching data from an incompletely signed zone could
			trigger an assertion failure in resolver.c [RT #33690]
  -	[security]	Support NAPTR regular expression validation on
			all platforms without using libregex, which
			can be vulnerable to memory exhaustion attack
			(CVE-2013-2266). [RT #32688]
  -	[security]	RPZ rules to generate A records (but not AAAA records)
			could trigger an assertion failure when used in
			conjunction with DNS64 (CVE-2012-5689). [RT #32141]
  -	[bug]		Fixed several Coverity warnings.
			Note: This change includes a fix for a bug that
			was subsequently determined to be an exploitable
			security vulnerability, CVE-2012-5688: named could
			die on specific queries with dns64 enabled.
			[RT #30996]
  -	[maint]		Added AAAA for D.ROOT-SERVERS.NET.
  -	[maint]		D.ROOT-SERVERS.NET is now 199.7.91.13.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=115
2013-06-26 10:50:27 +00:00