SHA256
1
0
forked from pool/bind
Commit Graph

295 Commits

Author SHA256 Message Date
7a18d2cf86 Accepting request 1005206 from home:jcronenberg:branches:network
- Update to bind release 9.18.7
  Security Fixes:
  * Previously, there was no limit to the number of database lookups
    performed while processing large delegations, which could be
    abused to severely impact the performance of named running as a
    recursive resolver. This has been fixed. (CVE-2022-2795)
  * When an HTTP connection was reused to request statistics from the
    stats channel, the content length of successive responses could
    grow in size past the end of the allocated buffer.
    This has been fixed. (CVE-2022-2881)
  * Memory leaks in code handling Diffie-Hellman (DH) keys were fixed
    that could be externally triggered, when using TKEY records in DH
    mode with OpenSSL 3.0.0 and later versions. (CVE-2022-2906)
  * named running as a resolver with the stale-answer-client-timeout
    option set to 0 could crash with an assertion failure, when there
    was a stale CNAME in the cache for the incoming query.
    This has been fixed. (CVE-2022-3080)
  * Memory leaks were fixed that could be externally triggered in the
    DNSSEC verification code for the EdDSA algorithm. (CVE-2022-38178)
  Feature Changes:
  * Response Rate Limiting (RRL) code now treats all QNAMEs that are
    subject to wildcard processing within a given zone as the same
    name, to prevent circumventing the limits enforced by RRL.
  * Zones using dnssec-policy now require dynamic DNS or
    inline-signing to be configured explicitly.
  * When reconfiguring dnssec-policy from using NSEC with an NSEC-only
    DNSKEY algorithm (e.g. RSASHA1) to a policy that uses NSEC3,
    BIND 9 no longer fails to sign the zone; instead, it keeps using
    NSEC until the offending DNSKEY records have been removed from the
    zone, then switches to using NSEC3.
  * A backward-compatible approach was implemented for encoding
    internationalized domain names (IDN) in dig and converting the
    domain to IDNA2008 form; if that fails, BIND tries an IDNA2003
    conversion.
  Bug Fixes:
  * A serve-stale bug was fixed, where BIND would try to return stale
    data from cache for lookups that received duplicate queries or
    queries that would be dropped. This bug resulted in premature
    SERVFAIL responses, and has now been resolved.
  This obsoletes the following patch:
  * bind-fix-mysql-bindings.patch
  [bsc#1203614, bsc#1203615, bsc#1203616, bsc#1203618, bsc#1203620]

OBS-URL: https://build.opensuse.org/request/show/1005206
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=357
2022-09-21 13:17:51 +00:00
b0d4a2d8fa Accepting request 998005 from home:jcronenberg:branches:network
- Fix typo in contrib/dlz/modules/{mysql,mysqldyn} that references
  LDAP_LIBS instead of MYSQL_LIBS.
  [bsc#1202149, bind.spec, bind-fix-mysql-bindings.patch]
- Update to bind release 9.18.6
  Bug Fixes:
  * When running as a validating resolver forwarding all queries
    to another resolver, named could crash with an assertion failure.
    These crashes occurred when the configured forwarder sent
    a broken DS response and named failed its attempts to find
    a proper one instead. This has been fixed.
  * Non-dynamic zones that inherit dnssec-policy from the view
    or options blocks were not marked as inline-signed
    and therefore never scheduled to be re-signed. This has been fixed.
  * The old max-zone-ttl zone option was meant to be superseded
    by the max-zone-ttl option in dnssec-policy; however,
    the latter option was not fully effective. This has been corrected:
    zones no longer load if they contain TTLs greater than the limit
    configured in dnssec-policy. For zones with both the old
    max-zone-ttl option and dnssec-policy configured,
    the old option is ignored, and a warning is generated.
  * rndc dumpdb -expired was fixed to include expired RRsets,
    even if stale-cache-enable is set to no and the cache-cleaning
    time window has passed.
  For a complete list of changes, see
  * Bind Release Notes
    https://downloads.isc.org/isc/bind9/9.18.6/doc/arm/html/notes.html
  * The CHANGES file in the source RPM
  [bind.spec bind-9.18.6.tar.xz bind-9.18.6.tar.xz.sha512.asc]

OBS-URL: https://build.opensuse.org/request/show/998005
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=355
2022-08-19 06:48:05 +00:00
76349528f7 Accepting request 992780 from home:jcronenberg:branches:network
- When enabling query_logging by un-commenting an example in
  bind.conf, named attempts to create a file in /var/log which
  fails due to missing credentials. This also applies to the
  "dump-file" and the "statistics-file".
  This is solved by having systemd-tmpfiles create a subdirectory
  "/var/log/named" owned by named:named and changing the file
  paths accordingly:
  /var/log/named_querylog -> /var/log/named/querylog
  /var/log/named_dump.db -> /var/log/named/dump.db
  /var/log/named.stats -> /var/log/named/stats
  Also, in "named.service", the ReadWritePath was changed to
  include "/var/log/named" rather than just "var/log".
  [bsc#1200685, bind.conf, vendor-files/config/named.conf,
   vendor-files/system/named.service]

OBS-URL: https://build.opensuse.org/request/show/992780
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=353
2022-08-04 14:25:35 +00:00
Reinhard Max
30add1cedb Accepting request 992008 from home:jcronenberg:branches:network
- Add systemd drop-in directory for named service

OBS-URL: https://build.opensuse.org/request/show/992008
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=351
2022-08-01 11:54:00 +00:00
713ad10142 Accepting request 990505 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/990505
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=349
2022-07-21 09:48:29 +00:00
b842fbd70f Accepting request 982818 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/982818
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=347
2022-06-18 13:08:27 +00:00
ed2f268e4c OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=345 2022-06-04 23:56:02 +00:00
b36054bf8e Accepting request 978142 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/978142
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=344
2022-05-21 19:35:27 +00:00
ed00a571eb Accepting request 977055 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/977055
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=342
2022-05-16 08:30:17 +00:00
d16c91b060 Accepting request 977464 from home:marxin:branches:network
- Add upstream patch bind-prevent-buffer-overflow.patch.

OBS-URL: https://build.opensuse.org/request/show/977464
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=341
2022-05-16 08:27:30 +00:00
9fc32bb7e7 Accepting request 973839 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/973839
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=340
2022-05-06 07:52:29 +00:00
de343e57f9 Accepting request 966391 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/966391
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=339
2022-04-12 15:01:39 +00:00
a049546ee4 Accepting request 963527 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/963527
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=338
2022-03-31 09:30:02 +00:00
a6a277bcef bind-contrib-pthread.patch, named-bootconf.diff, bind-define-missing-threads.patch]
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=337
2022-02-24 16:24:59 +00:00
33b4dc7ca1 Accepting request 952940 from home:jmoellers:branches:network
Tested on Tumbleweed and SLE-15-SP4

OBS-URL: https://build.opensuse.org/request/show/952940
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=336
2022-02-23 12:08:26 +00:00
Josef Möllers
0036f07039 Accepting request 947995 from home:gmbr3:Active
- Add now working CONFIG parameter to sysusers generator

OBS-URL: https://build.opensuse.org/request/show/947995
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=335
2022-01-24 09:32:08 +00:00
02c9c898db Accepting request 947678 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/947678
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=334
2022-01-21 15:47:38 +00:00
2a94c20c41 Accepting request 940767 from home:jmoellers:branches:network
Test on SLES15-SP4 and TW successful

OBS-URL: https://build.opensuse.org/request/show/940767
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=333
2021-12-27 09:24:49 +00:00
Josef Möllers
dd9425ce8e Accepting request 935515 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/935515
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=332
2021-12-03 15:42:52 +00:00
bc2ee8dcfd Accepting request 930088 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/930088
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=331
2021-11-28 19:18:24 +00:00
9ad6dc50bb Accepting request 926001 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/926001
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=330
2021-10-20 13:06:21 +00:00
2145ed9993 Accepting request 924636 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/924636
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=329
2021-10-15 12:25:01 +00:00
Josef Möllers
1bfcffcd13 Version
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=328
2021-08-27 12:44:24 +00:00
8965708ce8 Accepting request 913006 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/913006
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=327
2021-08-27 11:49:05 +00:00
Josef Möllers
690c3ba2eb Accepting request 909186 from home:polslinux:branches:network
- Update to 9.16.19
  * A race condition could occur where two threads were
    competing for the same set of key file locks, leading to
    a deadlock. This has been fixed. [GL #2786]
  * create_keydata() created an invalid placeholder keydata
    record upon a refresh failure, which prevented the
    database of managed keys from subsequently being read
    back. This has been fixed. [GL #2686]
  * KASP support was extended with the "check DS" feature.
    Zones with "dnssec-policy" and "parental-agents"
    configured now check for DS presence and can perform
    automatic KSK rollovers. [GL #1126]
  * Rescheduling a setnsec3param() task when a zone failed
    to load on startup caused a hang on shutdown. This has
    been fixed. [GL #2791]
  * The configuration-checking code failed to account for
    the inheritance rules of the "dnssec-policy" option.
    This has been fixed. [GL #2780]
  * If nsupdate sends an SOA request and receives a REFUSED
    response, it now fails over to the next available
    server. [GL #2758]
  * For UDP messages larger than the path MTU, named now
    sends an empty response with the TC (TrunCated) bit set.
    In addition, setting the DF (Don't Fragment) flag on
    outgoing UDP sockets was re-enabled. [GL #2790]
  * Views with recursion disabled are now configured with a
    default cache size of 2 MB unless "max-cache-size" is
    explicitly set. This prevents cache RBT hash tables from
    being needlessly preallocated for such views. [GL #2777]
  * Change 5644 inadvertently introduced a deadlock: when
    locking the key file mutex for each zone structure in a
    different view, the "in-view" logic was not considered.
    This has been fixed. [GL #2783]
  * Increasing "max-cache-size" for a running named instance
    (using "rndc reconfig") did not cause the hash tables
    used by cache databases to be grown accordingly. This
    has been fixed. [GL #2770]
  * Signed, insecure delegation responses prepared by named
    either lacked the necessary NSEC records or contained
    duplicate NSEC records when both wildcard expansion and
    CNAME chaining were required to prepare the response.
    This has been fixed. [GL #2759]
  * A bug that caused the NSEC3 salt to be changed on every
    restart for zones using KASP has been fixed. [GL #2725]

OBS-URL: https://build.opensuse.org/request/show/909186
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=326
2021-07-29 13:39:41 +00:00
31ed332cd7 Accepting request 907456 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/907456
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=325
2021-07-21 11:50:51 +00:00
2d1a8b1c56 Accepting request 901768 from home:frispete:15.2
Hi,

here's an attempt to build the current bind with SLES/LEAP.
I tried to come up with something mode decent (replacement of 
sphinx.util.docutils.ReferenceRole), but run out of time.
With these admittedly ugly fixes, bind does build at least, 
including the ARM, but that is missing the clickable issues
in the version specific notes and being redirected to GitLab.

- Add patch bind-fix-build-with-older-sphinx.patch and sed fix
  in order to build with older distributions.

OBS-URL: https://build.opensuse.org/request/show/901768
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=324
2021-06-28 07:10:05 +00:00
712466db64 Accepting request 900882 from home:gmbr3:Active
- Add now working CONFIG parameter to sysusers generator

OBS-URL: https://build.opensuse.org/request/show/900882
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=323
2021-06-28 07:07:57 +00:00
114c6c58ca Accepting request 901419 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/901419
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=322
2021-06-23 09:39:20 +00:00
1aa8a9bb85 Accepting request 894731 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/894731
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=320
2021-05-24 12:18:49 +00:00
163f048d16 Accepting request 892098 from home:susnux:branches:network
SPEC file: Fixed outdated URL and use secured SourceURLs

OBS-URL: https://build.opensuse.org/request/show/892098
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=318
2021-05-11 21:04:47 +00:00
Lars Vogdt
3e40d2b6ff Accepting request 880720 from home:jengelh:branches:network
- Modernize specfile, and declare /bin/bash as required buildshell
  (use of {a,b} style expansion).

OBS-URL: https://build.opensuse.org/request/show/880720
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=316
2021-05-09 12:35:56 +00:00
Reinhard Max
1539ed7f3f Accepting request 891297 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/891297
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=315
2021-05-07 12:26:49 +00:00
649063bcfa Accepting request 887164 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/887164
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=313
2021-04-30 11:15:37 +00:00
de638e5cf5 Accepting request 878586 from home:mgerstner:branches:network
- pass PIE compiler and linker flags via environment variables to make
  /usr/bin/delv in bind-tools also position independent (bsc#1183453).
- drop pie_compile.diff: no longer needed, this patch is difficult to
  maintain, the environment variable approach is less error prone.

OBS-URL: https://build.opensuse.org/request/show/878586
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=311
2021-03-23 11:05:30 +00:00
fc3480a7ee Accepting request 874900 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/874900
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=310
2021-03-03 07:12:48 +00:00
Josef Möllers
04b4ed4df0 Accepting request 866630 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/866630
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=308
2021-01-26 08:58:48 +00:00
Josef Möllers
b585e7fb90 Accepting request 859291 from home:dirkmueller:branches:network
- update to 9.16.10:
  New Features:
  * NSEC3 support was added to KASP. A new option for dnssec-policy,
  nsec3param, can be used to set the desired NSEC3 parameters. NSEC3 salt
  collisions are automatically prevented during resalting. [GL #1620]
  * A new configuration option, stale-refresh-time, has been introduced. It allows
  a stale RRset to be served directly from cache for a period of time after a
  failed lookup, before a new attempt to refresh it is made. [GL #2066]
  Feature Changes:
  * The default value of max-recursion-queries was increased from 75 to 100.
  Since the queries sent towards root and TLD servers are now included in the
  count (as a result of the fix for CVE-2020-8616), max-recursion-queries has
  a higher chance of being exceeded by non-attack queries, which is the main
  reason for increasing its default value. [GL #2305]
  The default value of nocookie-udp-size was restored back to 4096 bytes. Since
  max-udp-size is the upper bound for nocookie-udp-size, this change relieves the
  operator from having to change nocookie-udp-size together with max-udp-size in
  order to increase the default EDNS buffer size limit. nocookie-udp-size can
  still be set to a value lower than max-udp-size, if desired. [GL #2250]
  Bug Fixes:
  Handling of missing DNS COOKIE responses over UDP was tightened by falling
  back to TCP. [GL #2275]
  The CNAME synthesized from a DNAME was incorrectly followed when the QTYPE was
  CNAME or ANY. [GL #2280]
  Building with native PKCS#11 support for AEP Keyper has been broken since BIND
  9.16.6. This has been fixed. [GL #2315]
  named could crash with an assertion failure if a TCP connection were closed
  while a request was still being processed. [GL #2227]
  named acting as a resolver could incorrectly treat signed zones with no DS
  record at the parent as bogus. Such zones should be treated as insecure. This

OBS-URL: https://build.opensuse.org/request/show/859291
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=306
2021-01-07 11:50:54 +00:00
d00771e830 Accepting request 848814 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/848814
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=304
2020-12-05 17:16:58 +00:00
Josef Möllers
303deef25b Accepting request 843167 from home:jmoellers:branches:network
Upgrade

OBS-URL: https://build.opensuse.org/request/show/843167
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=302
2020-10-21 13:48:54 +00:00
Josef Möllers
8b606f05ee Accepting request 835836 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/835836
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=300
2020-09-21 14:22:51 +00:00
Josef Möllers
66e3fa8c5f Accepting request 835777 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/835777
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=299
2020-09-21 09:56:02 +00:00
9d471ca7a6 Accepting request 834667 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/834667
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=298
2020-09-18 07:23:46 +00:00
Reinhard Max
c7de7e258a - Put libns into a separate subpackage to avoid file conflicts
in the libisc subpackage due to different sonums (bsc#1176092).

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=297
2020-09-04 14:42:49 +00:00
OBS User buildservice-autocommit
1d647cd766 Updating link to change in openSUSE:Factory/bind revision 156.0
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=90c94fa850d01fd39b0d70b750cd34f4
2020-09-01 07:49:42 +00:00
Reinhard Max
c61c37b69f Accepting request 830239 from home:dimstar:Factory
- Require /sbin/start_daemon: both init scripts, the one used in
  systemd context as well as legacy sysv, make use of start_daemon.

OBS-URL: https://build.opensuse.org/request/show/830239
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=295
2020-08-28 10:01:48 +00:00
Josef Möllers
cc91d0126a Accepting request 828392 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/828392
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=294
2020-08-21 08:19:08 +00:00
Josef Möllers
c10343c1a5 Accepting request 824686 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/824686
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=292
2020-08-17 06:19:40 +00:00
Josef Möllers
a7358e2599 Accepting request 822197 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/822197
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=290
2020-07-22 12:17:29 +00:00
Reinhard Max
13336b5b52 Accepting request 819259 from home:jmoellers:branches:network
OBS-URL: https://build.opensuse.org/request/show/819259
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=289
2020-07-21 07:32:24 +00:00