Commit Graph

26 Commits

Author SHA1 Message Date
Vincent Li
9d20e54edc knot: upgrade to 3.4.7
enable XDP and add kxdpgun utility for dnsdist AF_XDP performance
test [0]

[0]: https://www.dnsdist.org/advanced/xsk.html

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2025-06-23 10:07:29 -07:00
Adolf Belka
374b2d8d57 knot: Update to version 3.3.8
- Update from version 3.3.5 to 3.3.8
- Update of rootfile not required
- Changelog
    3.3.8
	Features:
	 - libzscanner,libknot: added support for 'dohpath' and 'ohttp' SVCB parameters
	 - libzscanner,libknot: added support for WALLET rrtype
	 - keymgr: new commands for keystore testing (see 'keystore-test' and 'keystore-bench')
	 - knotd: new configuration option for setting default TTL (see 'zone.default-ttl')
	Improvements:
	 - libknot: added error codes to better describe some failures
	Bugfixes:
	 - knotd: DNSSEC signing doesn't remove NSEC records for non-authoritative nodes
	 - knotd: DNSSEC signing not scheduled on secondary if nothing to be reloaded
	 - libknot: TCP over XDP doesn't ignore SYN+ACK packets on the server side
    3.3.7
	Improvements:
	 - libs: upgraded embedded libngtcp2 to 1.6.0
	Bugfixes:
	 - knotd: insufficient metadata check can cause journal corruption
	 - knotd: missing zone timers initialization upon purge
	 - knotd: missing RCU lock in zone flush and refresh
	 - knotd: defective assert in zone refresh
    3.3.6
	Features:
	 - knotd: configurable control socket backlog size (see 'control.backlog')
	 - knotd: optional configuration of congruency of generated keytags (see 'policy.keytag-modulo')
	 - knotc: support for exporting configuration schema in JSON (see 'conf-export') #912
	 - mod-dnstap: configuration of sink allows TCP address specification
	Improvements:
	 - knotd: last-signed serial is stored to KASP even if not a secondary zone
	 - knotd: allowed catalog role member in a catalog template configuration
	 - knotd: some references in a zone configuration can be set empty to override a template
	 - knotd: allowed zone backup during a zone transaction
	 - knotd: add remote TSIG key name to outgoing event logs
	 - knotc: zone backup with '+keysonly' silently uses all defaults as 'off'
	 - kxdpgun: host name can be used for target specification
	 - libs: upgraded embedded libngtcp2 to 1.5.0
	 - doc: various fixes and updates
	Bugfixes:
	 - knotd: reset TCP connection not removed from a connection pool
	 - knotd: server wrongly tries to remove removed ZONEMD
	 - knotd: failed to parse empty list from a textual configuration
	 - knotd: blocking zone signing in combination with an open transaction causes a deadlock
	 - knotd: missing RCU lock when sending NOTIFY
	 - kdig: QNAME letter case isn't preserved if IDN is enabled
	 - kdig: failed to parse empty QNAME (do not fill question section)
	 - kxdpgun: floating point exception on SIGUSR1 #927
	 - libknot: incorrect handling of regular QUIC tokens in incoming initials
	 - python: failed to set an empty configuration value

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-08-14 09:09:54 +00:00
Adolf Belka
025cf4aafc knot: Update to version 3.3.5
- Update from version 3.2.4 to 3.3.5
- Update of rootfile
- Changelog
    3.3.5 (2024-03-06)
	Features:
	 - knotd: new module mod-authsignal for automatic authenticated DNSSEC
	          bootstrapping records synthesis (Thanks to Peter Thomassen)
	 - kzonecheck: new optional ZONEMD verification (see option '-z')
	Improvements:
	 - knotd: new DNSSEC key rollover log informs about next planned key action
	 - knotd, kzonecheck: added limit on non-matching keys with a duplicate keytag
	 - knot-exporter: added counter-type variant for each metric (Thanks to Marcel Koch)
	 - libs: upgraded embedded libngtcp2 to 1.3.0
	 - doc: various fixes and updates
	Bugfixes:
	 - knotd, kzonecheck: failed to validate RRSIG if there are more keys with the same keytag
	 - knotd, kzonecheck: failed to validate zone with more CSK keys
	 - libknot: insufficient check for malformed TCP header options over XDP
    3.3.4 (2024-01-24)
	Features:
	 - knotd: new configuration item for clearing configuration sections (see 'clear')
	 - knotc: configuration import can preserve database contents (see '+nopurge' flag)
	 - kxdpgun: new parameter for setting UDP payload size in EDNS (see '--edns-size') #915
	Improvements:
	 - knotd: extended configuration check for 'zonefile-load' and 'journal-content'
	 - knotd: lowered check limit for additional NSEC3 iterations to 0
	 - knotd: lowered severity level of an informational backup log
	 - knotd: better log message when flushing the journal
	 - knotd: zone restore checks if requested contents are in the provided backup
	 - knotc: '+quic' is default for zone backup, '+noquic' is default for zone restore
	 - kdig: better processing of timeouts and reduced sent datagrams over QUIC
	 - kdig: no retries are attempted over QUIC
	 - keymgr: improved compatibility with bind9-generated keys
	 - libs: some improvements in XDP buffer allocation
	 - libs: upgraded embedded libngtcp2 to 1.2.0
	 - doc: various fixes and updates
	Bugfixes:
	 - knotd: failed to build on macOS #909
	 - knotd: 'nsec3-salt-lifetime: -1' doesn't work if 'ixfr-from-axfr' is enabled
	 - knotd: unnecessarily updated RRSIGs if 'ixfr-from-axfr' and signing are enabled
	 - knotc: zone check complains about missing zone file #913
	 - kdig: failed to try another target address over QUIC
	 - libknot: infinite loop in knot_rrset_to_wire_extra() #916
    3.3.3 (2023-12-13)
	Features:
	 - knotd: new 'pattern' mode of ACL update owner matching (see 'acl.update-owner-match')
	 - knotc: new '+keysonly' filter for zone backup/restore
	Improvements:
	 - knotd: zone purging waits for finished zone expiration for better reliability
	 - knotd: remote configuration considers more 'via' with the same address family
	 - knotd: refresh doesn't fall back from IXFR to AXFR upon a network error
	 - knotd: increased default for 'policy.rrsig-refresh' by (0.1 * 'rrsig-lifetime')
	 - knotd: new control flag 'u' for unix time output format from zone status
	 - knotd: extended check for inconsistent acl settings
	 - knotd/libknot: simplified TCP/QUIC sweep logging
	 - mod-dnsproxy: all configured remote addresses are used for fallback operation
	 - mod-dnsproxy: module responds locally if forwarding fails instead of SERVFAIL
	 - libs: upgraded embedded libngtcp2 to 1.1.0
	 - doc: various fixes and extensions
	Bugfixes:
	 - knotd: zone backup fails due to improper backup context deinitialization #891
	 - knotd: failed to sign the zone if maximum zone's TTL is too high
	 - knotd: malformed TCP header if used with QUIC in the generic XDP mode
	 - knotd: server can crash when processing new TCP connections over XDP
	 - knotd: incorrect initialization of TCP limits
	 - knotd: orphaned PEM file not deleted when key generation fails
	 - knotd/libknot: connection timeouts over QUIC due to incomplete retransfer handling #894
	 - kdig: crashed when querying DNS over TLS if TLS handshake times out #896
	 - kzonecheck: failed to check DS with SHA-1 or GOST if not supported by local policy
	 - libdnssec: failed to compile with GnuTLS if PKCS #11 support is disabled
    3.3.2 (2023-10-20)
	Features:
	 - knotd: support for IXFR from AXFR computation (see 'zone.ixfr-from-axfr')
	 - knotd: support benevolent IXFR (see 'zone.ixfr-benevolent')
	 - knot-exporter: new configuration option '--no-zone-serial' #880
	Improvements:
	 - libs: upgraded embedded libngtcp2 to 1.0.0
	 - knotd: added logging of new SOA serial when signing is finished
	 - knotd: unified some XDP-related logging
	 - keymgr: improved error message if a key file is not accessible
	 - keymgr: added offline RRSIGs validation at the end of their validity intervals
	 - kdig: upgraded EDNS presentation format to draft version -02
	 - kdig: simplified QUIC connection without extra PING frames
	 - kzonecheck: removed requirement that DS is at delegation point
	 - doc: various fixes and improvements
	Bugfixes:
	 - knotd: logged incorrect new SOA serial if 'zonefile-load: difference' is set #875
	 - knotd: more signing threads with a PKCS #11 keystore has no effect #876
	 - knotd: DNAME record returned with query domain name instead of actual name #873
	 - knotd: failed to import configuration file if mod-geoip is in use  #881
	 - knotd: failed to sign RRSet that fits to 64k only if compressed
	 - knotd: broken zone update context upon failed operation over control interface
	 - keymgr: offline RRSIGs not refreshed if 'rrsig-refresh' is not set
	 - knsupdate: incorrect processing of @ in the delete operation #879
	 - knot-exporter: failed to parse knotd PIDs on FreeBSD
	Packaging:
	 - docker: added support for (inter-container) D-Bus signaling
    3.3.1 (2023-09-11)
	Improvements:
	 - knotd: multiple catalog groups per member are tolerated, but only one is used
	 - modules: added const qualifier to various function parameters #877 (Thanks to Robert Edmonds)
	 - libs: upgraded embedded libngtcp2 to 0.19.1
	Bugfixes:
	 - knotd: TCP over XDP fails to respond
	 - knotd: server can crash when adjusting a wildcard glue
	 - knotd: failed to forward DDNS if 'zone.master' points to 'remotes'
	 - knotd: broken YAML statistics if more modules are configured #874
	 - knotd: DDNS forwarding isn't RFC 8945 compliant
    3.3.0 (2023-08-28)
	Features:
	 - knotd: full DNS over QUIC (DoQ, RFC 9250) implementation, also without XDP
	 - knotd: bidirectional XFR over QUIC (XoQ) support with opportunistic, strict,
	          and mutual authentication profiles
	 - knotd: automatic reverse PTR records pre-generation (see 'zone.reverse-generate')
	 - knotd: new per zone statistic counters 'zone.size' and 'zone.max-ttl'
	 - knotd: new primary server pinning (see 'zone.master-pin-tolerance')
	 - knotd: new SOA serial modulo policy (see 'zone.serial-modulo')
	 - knotd: new multi-signer operation mode (see 'policy.dnskey-sync' and 'DNSSEC multi-signer')
	 - kdig: support for EDNS presentation format, also in JSON mode (see '+optpresent')
	 - kxdpgun: new TCP/QUIC debug mode 'R' for connection reuse
	 - kxdpgun: new XDP mode parameter '--mode' (Thanks to Jan Včelák)
	 - kxdpgun: new parameter '--qlog' for qlog destination specification
	 - kzonecheck: new '--print' parameter for dumping the zone on stdout
	Improvements:
	 - knotd: secondary can be configured not to forward DDNS (see 'zone.ddns-master')
	 - knotd: extended support for UNIX socket configuration (remote, acl)
	 - knotd: stats no longer dump empty or zero counters
	 - knotd: new 'keys-updated' D-Bus event
	 - knotd: added transport protocol information to outgoing event and nameserver logs
	 - knotd: server cleans up stale LMDB readers when opening a RW transaction
	 - knotd,kzonecheck: semantic check allows DS only at delegation point
	 - knotc: new zone backup filters '+quic' and '+noquic' for QUIC key backup
	 - mod-dnstap: DNS over QUIC traffic is marked as QUIC
	 - kxdpgun: QUIC connections are closed by default
	 - libs: upgraded embedded libngtcp2 to 0.18.0
	 - kdig: QUIC, TLS, or HTTPS protocol is printed in the final statistics
	 - doc: new sections 'DNS over QUIC' and 'DNSSEC multi-signer'
	 - doc: various improvements
	Bugfixes:
	 - knotd: server can crash if a shared module is loaded and dynamic configuration used
	 - knotd: inaccurate transfer size is logged if EDNS EXPIRE, PADDING, or TSIG is present
	 - knotd: subsequent addition and removal to catalog zone isn't handled properly
	 - knotc: configuration import fails if an explicit shared module is configured
	 - utils: database transactions not properly closed when terminated prematurely
	 - kdig: double-free on some malformed responses over QUIC #869
	 - kdig: some TLS parameters override QUIC parameters
	 - libs: NULL record with empty RDATA isn't allowed
	 - tests: dthreads destructor test sometimes fails
	Compatibility:
	 - knotd: responses to forwarded DDNS requests are signed with local TSIG key
	 - knotd: NOTIFY-initiated refresh tries all configured addresses of the remote
	 - knotd: configuration option 'xdp.quic-log' was replaced with 'log.quic'
	 - libs: removed embedded libbpf, an external one is necessary for XDP
	 - libs: DNS over QUIC implementation only supports 'doq' ALPN
	 - ctl: removed 'Version: ' prefix from 'status version' output
	 - modules: reduced parameters of 'knotd_qdata_local_addr()'
	Packaging:
	 - knot-exporter: Prometheus exporter imported from GitHub
	 - knot-exporter: packages for Debian, Ubuntu, and PyPI
	 - debian,ubuntu: new self-hosted repository (see https://pkg.labs.nic.cz/doc/)
	 - docker: upgraded to Debian bookworm-slim
    3.2.9 (2023-07-27)
	Improvements:
	 - keymgr: 'import-pkcs11' not allowed if no PKCS #11 keystore backend is configured
	 - keymgr: more verbose key import errors
	 - doc: extended migration notes
	 - doc: various improvements
	Bugfixes:
	 - knotd: server may crash when storing changeset of a big zone migrating to/from NSEC3
	 - knotd: zone refresh loop when all masters are outdated and timers cleared
	 - knotd: failed to active D-Bus notifications if not started as systemd service
	 - kjournalprint: database transaction not properly closed when terminated prematurely
    3.2.8 (2023-06-26)
	Improvements:
	 - kdig: malformed messages are parsed and printed using a best-effort approach
	 - python: new dname from wire initialization
	Bugfixes:
	 - knotd: missing outgoing NOTIFY upon refresh if one of more primaries is up-to-date
	 - knotd: journal loop detection can prevent zone from loading
	 - knotd: cryptic error message when journal is full #842
	 - knotd: failed to query catalog zone over UDP
	 - configure: libngtcp2 check wrongly requires version 0.13.0 instead of 0.13.1
    3.2.7 (2023-06-06)
	Features:
	 - knotd: new configuration option for preserving incoming IXFR changeset history
	          (see 'zone.ixfr-by-one')
	Improvements:
	 - knotd: journal ensures the stored changeset's SOA serials are strictly increasing
	 - knotd: more effective handling of zero KNOT_ZONE_LOAD_TIMEOUT_SEC environment value
	 - knotd, kdig: incoming transfer fails if a message has the TC bit set
	 - knotd, kjournalprint: store or print the timestamp of changeset creation
	 - kxdpgun: load only necessary number of queries (Thanks to Petr Špaček)
	 - kxdpgun: print ratio of sent vs. requested queries (Thanks to Petr Špaček)
	 - kxdpgun: print percentages as floats (Thanks to Petr Špaček)
	 - kjournalprint: ability to print a changeset loop
	 - kjournalprint: added changset serials information to '-z -d' output
	 - packaging: RHEL9 requires libxdp like fedora since RHEL 9.2 #844
	 - doc: various improvements
	Bugfixes:
	 - knotd: journal loading can get stuck in a multi-changeset loop
	 - knotd: missing RCU lock when reading zone through the control interface
	 - knotd: server start D-Bus signaling doesn't work well if the zone file is
	          missing, catalog zones are used, or in the async-start mode
	 - knotd: test suite fails on 32bit architectures on musl 1.2 and newer #843
	 - knotd: failed to process zero-length messages over QUIC
	 - libs: compilation with embedded ngtcp2 fails if there is another ngtcp2 in the path
    3.2.6 (2023-04-04)
	Improvements:
	 - libs: upgraded embedded libngtcp2 to 0.13.1
	 - libs: added support for building on Cygwin and MSYS (Thanks to Christopher Ng)
	 - mod-dnstap: improved precision of stored time values
	 - kdig: added option for EDNS EXPIRE (see '+expire') #836
	 - kdig: extended description of SOA timers in the multiline mode
	 - kdig: reduced latency of TLS communication
	 - libknot: added EDE codes 28 and 29
	 - doc: various improvements
	Bugfixes:
	 - knotd: generated catalog zone not updated upon server reload #834
	 - knotd: failed to check shared module configuration
	 - knotd: missing RCU registration of the statistics thread (Thanks to Qin Longfei)
	 - knotd: server logs failed to send QUIC packets in the XDP mode
	 - libs: inconsistent transformation of IPv4-Compatible IPv6 Addresses
	 - utils: failed to load configuration if dnstap module is enabled #831
	 - libknot: missing include string.h
    3.2.5 (2023-02-02)
	Features:
	 - knotd: new configuration option for enforcing IXFR fallback (see 'zone.provide-ixfr')
	Improvements:
	 - knotd: changed UNIX socket file mode to 0222 for answering and 0220 for control
	 - mod-probe: new support for communication over a UNIX socket
	 - kdig: new support for communication over a UNIX socket
	 - libs: upgraded embedded libngtcp2 to 0.13.0
	 - doc: various improvements
	Bugfixes:
	 - knotd: failed to get catalog member configuration if catalog template is in a template
	 - knotd: failed to respond over a UNIX socket with EDNS
	 - knotd: unexpected zone update upon restart or zone reload if ZONEMD generation is enabled
	 - knotd: redundant zone flush of unchanged zone if zone file load is 'difference-no-serial'
	 - knotd/kxdpgun: failed to receive messages over XDP with drivers tap or ena
	 - knotc: zone check doesn't report missing zone file #829
	 - kxdpgun: program crashes when remote closes QUIC connection instead of resumption
	 - mod-geoip: configuration check leaks memory in the geodb mode
	 - utils: unwanted color reset sequences in non-color output

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-03-12 10:12:29 +00:00
Adolf Belka
3816b8b5bc knot: Update to version 3.2.4
- Update from version 3.1.7 to 3.2.4
- Update of rootfile
- find-dependencies run and only thing showing as depending on the libs are knot itself.
- Changelog
    Knot DNS 3.2.4 (2022-12-12)
	Improvements:
	 - knotd: significant speed-up of catalog zone update processing
	 - knotd: new runtime check if RRSIG lifetime is lower than RRSIG refresh
	 - knotd: reworked zone re-bootstrap scheduling to be less progressive
	 - mod-synthrecord: module can work with CIDR-style reverse zones #826
	 - python: new libknot wrappers for some dname transformation functions
	 - doc: a few fixes and improvements
	Bugfixes:
	 - knotd: incomplete zone is received when IXFR falls back to AXFR due to
	          connection timeout if primary puts initial SOA only to the first message
	 - knotd: first zone re-bootstrap is planned after 24 hours
	 - knotd: EDNS EXPIRE option is present in outgoing transfer of a catalog zone
	 - knotd: catalog zone can expire upon EDNS EXPIRE processing
	 - knotd: DNSSEC signing doesn't fail if no offline KSK records available
    Knot DNS 3.2.3 (2022-11-20)
	Improvements:
	 - knotd: new per-zone DS push configuration option (see 'zone.ds-push')
	 - libs: upgraded embedded libngtcp2 to 0.11.0
	Bugfixes:
	 - knsupdate: program crashes when sending an update
	 - knotd: server drops more responses over UDP under higher load
	 - knotd: missing EDNS padding in responses over QUIC
	 - knotd: some memory issues when handling unusual QUIC traffic
	 - kxdpgun: broken IPv4 source subnet processing
	 - kdig: incorrect handling of unsent data over QUIC
    Knot DNS 3.2.2 (2022-11-01)
	Features:
	 - knotd,kxdpgun: support for VLAN (802.1Q) traffic in the XDP mode
	 - knotd: added configurable delay upon D-Bus initialization (see 'server.dbus-init-delay')
	 - kdig: support for JSON (RFC 8427) output format (see '+json')
	 - kdig: support for PROXYv2 (see '+proxy') (Gift for Peter van Dijk)
	Improvements:
	 - mod-geoip: module respects the server configuration of answer rotation
	 - libs: upgraded embedded libngtcp2 to 0.10.0
	 - tests: improved robustness of some unit tests
	 - doc: added description of zone bootstrap re-planning
	Bugfixes:
	 - knotd: catalog confusion when a member is added and immediately deleted #818
	 - knotd: defective handling of short messages with PROXYv2 header #816
	 - knotd: inconsistent processing of malformed messages with PROXYv2 header #817
	 - kxdpgun: incorrect XDP mode is logged
	 - packaging: outdated dependency check in RPM packages
    Knot DNS 3.2.1 (2022-09-09)
	Improvements:
	 - libknot: added compatibility with libbpf 1.0 and libxdp
	 - libknot: removed some trailing white space characters from textual RR format
	 - libs: upgraded embedded libngtcp2 to 0.8.1
	Bugfixes:
	 - knotd: some non-DNS packets not passed to OS if XDP mode enabled
	 - knotd: inappropriate log about QUIC port change if QUIC not enabled
	 - knotd/kxdpgun: various memory leaks related to QUIC and TCP
	 - kxdpgun: can crash at high rates in emulated XDP mode
	 - tests: broken XDP-TCP test on 32-bit platforms
	 - kdig: failed to build with enabled QUIC on OpenBSD
	 - systemd: failed to start server due to TemporaryFileSystem setting
	 - packaging: missing knot-dnssecutils package on CentOS 7
    Knot DNS 3.2.0 (2022-08-22)
	Features:
	 - knotd: finalized TCP over XDP implementation
	 - knotd: initial implementation of DNS over QUIC in the XDP mode (see 'xdp.quic')
	 - knotd: new incremental DNSKEY management for multi-signer deployment (see 'policy.dnskey-management')
	 - knotd: support for remote grouping in configuration (see 'groups' section)
	 - knotd: implemented EDNS Expire option (RFC 7314)
	 - knotd: NSEC3 salt is changed with every ZSK rollover if lifetime is set to -1
	 - knotd: support for PROXY v2 protocol over UDP (Thanks to Robert Edmonds) #762
	 - knotd: support for key labels with PKCS #11 keystore (see 'keystore.key-label')
	 - knotd: SVCB/HTTPS treatment according to draft-ietf-dnsop-svcb-https
	 - keymgr: new JSON output format (see '-j' parameter) for listing keys or zones (Thanks to JP Mens)
	 - kxdpgun: support for DNS over QUIC with some testing modes (see '-U' parameter)
	 - kdig: new DNS over QUIC support (see '+quic')
	Improvements:
	 - knotd: reduced memory consumption when processing IXFR, DNSSEC, catalog, or DDNS
	 - knotd: RRSIG refresh values don't have to match in the mode Offline KSK
	 - knotd: better decision whether AXFR fallback is needed upon a refresh error
	 - knotd: NSEC3 resalt event was merged with the DNSSEC event
	 - knotd: server logs when the connection to remote was taken from the pool
	 - knotd: server logs zone expiration time when the zone is loaded
	 - knotd: DS check verifies removal of old DS during algorithm rollover
	 - knotd: DNSSEC-related records can be updated via DDNS
	 - knotd: new 'xdp.udp' configuration option for disabling UDP over XDP
	 - knotd: outgoing NOTIFY is replanned if failed
	 - knotd: configuration checks if zone MIN interval values are lower or equal to MAX ones
	 - knotd: DNSSEC-related zone semantic checks use DNSSEC validation
	 - knotd: new configuration value 'query' for setting ACL action
	 - knotd: new check on near end of imported Offline KSK records
	 - knotd/knotc: implemented zone catalog purge, including orphaned member zones
	 - knotc: interactive mode supports catalog zone completion, value completion, and more
	 - knotc: new default brief and colorized output from zone status
	 - knotc: unified empty values in zone status output
	 - keymgr: DNSKEY TTL is taken from KSR in the Offline KSK mode
	 - kjournalprint: path to journal DB is automatically taken from the configuration,
	                  which can be specified using '-c', '-C' (or '-D')
	 - kcatalogprint: path to catalog DB is automatically taken from the configuration,
	                  which can be specified using '-c', '-C' (or '-D')
	 - kzonesign: added automatic configuration file detection and '-C' parameter
	              for configuration DB specificaion
	 - kzonesign: all CPU threads are used for DNSSEC validation
	 - libknot: dname pointer cannot point to another dname pointer when encoding RRsets #765
	 - libknot: QNAME case is preserved in knot_pkt_t 'wire' field (Thanks to Robert Edmonds) #780
	 - libknot: reduced memory consumption of the XDP mode
	 - libknot: XDP filter supports up to 256 NIC queues
	 - kxdpgun: new options for specifying source and remote MAC addresses
	 - utils: extended logging of LMDB-related errors
	 - utils: improved error outputs
	 - kdig: query has AD bit set by default
	 - doc: various improvements
	Bugfixes:
	 - knotd: zone changeset is stored to journal even if disabled
	 - knotd: journal not applied to zone file if zone file changed during reload
	 - knotd: possible out-of-order processing or postponed zone events to far future
	 - knotd: incorrect TTL is used if updated RRSet is empty over control interface
	 - knotd/libs: serial arithmetics not used for RRSIG expiration processing
	 - knsupdate: incorrect RRTYPE in the question section
	Compatibility:
	 - knotd: default value for 'zone.journal-max-depth' was lowered to 20
	 - knotd: default value for 'policy.nsec3-iterations' was lowered to 0
	 - knotd: default value for 'policy.rrsig-refresh' is propagation delay + zone maximum TTL
	 - knotd: server fails to load configuration if 'policy.rrsig-refresh' is too low
	 - knotd: configuration option 'server.listen-xdp' has no effect
	 - knotd: new configuration check on deprecated DNSSEC algorithm
	 - knotc: new '-e' parameter for full zone status output
	 - keymgr: new '-e' parameter for full key list output
	 - keymgr: brief key listing mode is enabled by default
	 - keymgr: renamed parameter '-d' to '-D'
	 - knsupdate: default TTL is set to 3600
	 - knsupdate: default zone is empty
	 - kjournalprint: renamed parameter '-c' to '-H'
	 - python/libknot: removed compatibility with Python 2
	Packaging:
	 - systemd: removed knot.tmpfile
	 - systemd: added some hardening options
	 - distro: Debian 9 and Ubuntu 16.04 no longer supported
	 - distro: packages for CentOS 7 are built in a separate COPR repository
	 - kzonecheck/kzonesign/knsec3hash: moved to new package knot-dnssecutils
    Knot DNS 3.1.9 (2022-08-10)
	Improvements:
	 - knotd: new configuration checks on unsupported catalog settings
	 - knotd: semantic check issues have notice log level in the soft mode
	 - keymgr: command generate-ksr automatically sets 'from' parameter to last
	           offline KSK records' timestamp if it's not specified
	 - keymgr: command show-offline starts from the first offline KSK record set
	           if 'from' parameter isn't specified
	 - kcatalogprint: new parameters for filtering catalog or member zone
	 - mod-probe: default rate limit was increased to 100000
	 - libknot: default control timeout was increased to 30 seconds
	 - python/libknot: various exceptions are raised from class KnotCtl
	 - doc: some improvements
	Bugfixes:
	 - knotd: incomplete outgoing IXFR is responded if journal history is inconsistent
	 - knotd: manually triggered zone flush is suppressed if disabled zone synchronization
	 - knotd: failed to configure XDP listen interface without port specification
	 - knotd: de-cataloged member zone's file isn't deleted #805
	 - knotd: member zone leaks memory when reloading catalog during dynamic configuration change
	 - knotd: server can crash when reloading modules with DNSSEC signing (Thanks to iqinlongfei)
	 - knotd: server crashes during shutdown if PKCS #11 keystore is used
	 - keymgr: command del-all-old isn't applied to all keys in the removed state
	 - kxdpgun: user specified network interface isn't used
	 - libs: fixed compilation on illumos derivatives (Thanks to Nick Ewins)
    Knot DNS 3.1.8 (2022-04-28)
	Features:
	 - knotd: optional automatic ACL for XFR and NOTIFY (see 'remote.automatic-acl')
	 - knotd: new soft zone semantic check mode for allowing defective zone loading
	 - knotc: added zone transfer freeze state to the zone status output
	Improvements:
	 - knotd: added configuration check for serial policy of generated catalogs
	Bugfixes:
	 - knotd/libknot: the server can crash when validating a malformed TSIG record
	 - knotd: outgoing zone transfer freeze not preserved during server reload
	 - knotd: catalog UPDATE not processed if previous UPDATE processing not finished #790
	 - knotd: zone refresh not started if planned during server reload
	 - knotd: generated catalogs can be queried over UDP
	 - knotd/utils: failed to open LMDB database if too many stale slots occupy the lock table

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
2023-01-09 18:35:20 +00:00
Matthias Fischer
e56de75e33 knot: Update to 3.1.7
For changes since v3.1.1 see:
https://gitlab.nic.cz/knot/knot-dns/raw/v3.1.7/NEWS

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
2022-04-23 14:24:13 +00:00
Peter Müller
9a7e4d8506 Switch checksums from MD5 to BLAKE2
Historically, the MD5 checksums in our LFS files serve as a protection
against broken downloads, or accidentally corrupted source files.

While the sources are nowadays downloaded via HTTPS, it make sense to
beef up integrity protection for them, since transparently intercepting
TLS is believed to be feasible for more powerful actors, and the state
of the public PKI ecosystem is clearly not helping.

Therefore, this patch switches from MD5 to BLAKE2, updating all LFS
files as well as make.sh to deal with this checksum algorithm. BLAKE2 is
notably faster (and more secure) than SHA2, so the performance penalty
introduced by this patch is negligible, if noticeable at all.

In preparation of this patch, the toolchain files currently used have
been supplied with BLAKE2 checksums as well on
https://source.ipfire.org/.

Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremeripfire.org>
2022-04-02 14:19:25 +00:00
Peter Müller
66c3619872 Early spring clean: Remove trailing whitespaces, and correct licence headers
Bumping across one of our scripts with very long trailing whitespaces, I
thought it might be a good idea to clean these up. Doing so, some
missing or inconsistent licence headers were fixed.

There is no need in shipping all these files en bloc, as their
functionality won't change.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2022-02-18 23:54:57 +00:00
Matthias Fischer
e8c75ca765 knot: Update to 3.1.1
For changes since 3.0.7, see:
https://gitlab.nic.cz/knot/knot-dns/raw/v3.1.1/NEWS

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
2021-11-19 07:07:18 +01:00
Matthias Fischer
9e1f2150df knot: Update to 3.0.7
For details see:
https://www.knot-dns.cz/2021-06-16-version-307.html

Features:

        knotd: new configuration policy option for CDS digest algorithm setting #738
        keymgr: new command for primary SOA serial manipulation in on-secondary signing mode

Improvements:

        knotd: improved algorithm rollover to shorten the last step of old RRSIG publication

Bugfixes:

        knotd: zone is flushed upon server start, despite DNSSEC signing is up-to-date
        knotd: wildcard nonexistence is proved on empty-non-terminal query
        knotd: redundant wildcard proof for non-authoritative data in a reply
        knotd: missing wildcard proofs in a wildcard-cname loop reply
        knotd: incorrectly synthesized CNAME owner from a wildcard record #715
        knotd: zone-in-journal changeset ignores journal-max-usage limit #736
        knotd: incorrect processing of zone-in-journal changeset with SOA serial 0
        knotd: broken initialization of processing workers if SO_REUSEPORT(_LB) not available
        kjournalprint: reported journal usage is incorrect #736
        keymgr: cannot parse algorithm name ed448 #739
        keymgr: default key size not set properly
        kdig: failed to process huge DoH responses
        libknot/probe: some corner-case bugs

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-06-20 12:37:48 +00:00
Matthias Fischer
7966faf398 knot: Update to 3.0.6
For details see:
https://www.knot-dns.cz/2021-05-12-version-306.html

"Features:

        mod-probe: new module for simple traffic logging (Python API not yet included)

Improvements:

        keymgr: new mode for listing zones with at least one key stored
        keymgr: the pregenerate command accepts optional timestamp-from parameter
        kzonecheck: accept '-' as substitution for standard input #727
        knotd: print an error when unable to change owner of a logging file
        knotd: new warning log if no interface is configured
        knotd: new signing policy check for NSEC3 iterations higher than 20
        knotd: don't allow backup to/restore from the DB storage directory
        Various code (mostly zone backup/restore), tests, and documentation improvements

Bugfixes:

        knotd: secondary fails to load zone file if HTTPS or SVCB record is present #725
        knotd: (KSK roll-over) new KSK is not signing DNSKEY long enough before DS submission
        knotd: (KSK roll-over) old KSK uselessly published after roll-over finished
        knotd: malformed address in TCP-related logs when listening on a UNIX socket
        knotd: server responds FORMERR instead of BADTIME if TSIG signed time is zero #730
        modules: incorrect local and remote addresses in the XDP mode
        modules: failed to read configuration from a section without identifiers
        mod-synthrecord: queries on synthesized empty-non-terminals not answered with NODATA
        keymgr: confusing error if del-all-old command fails"

For 3.0.5 (skipped):
https://www.knot-dns.cz/2021-03-25-version-305.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-05-31 12:37:22 +00:00
Matthias Fischer
b3a4ea2817 knot: Update to 3.0.4
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-02-01 10:36:06 +00:00
Matthias Fischer
b1f5103899 knot: Cosmetic changes in lfs
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-02-01 10:35:57 +00:00
Matthias Fischer
3d725ebbec knot: Update to 3.0.3
For details see:
https://www.knot-dns.cz/2020-12-15-version-303.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-01-03 11:17:46 +00:00
Matthias Fischer
1e036ee90d knot: Update to 3.0.2
for details see:
https://www.knot-dns.cz/2020-11-11-version-302.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-11-27 15:50:29 +00:00
Matthias Fischer
dd4093dcf3 knot: Update to 3.0.1
For details see:
https://www.knot-dns.cz/2020-10-10-version-301.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-12 10:07:02 +00:00
Matthias Fischer
de27aa4731 knot: Update to 3.0.0
For details see:
https://www.knot-dns.cz/2020-09-09-version-300.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-09-24 17:36:38 +00:00
Matthias Fischer
ab18aa6485 knot: Update to 2.9.6
For details see:
https://www.knot-dns.cz/2020-08-31-version-296.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-09-24 17:36:38 +00:00
Matthias Fischer
fead20a917 knot: Update to 2.9.5
For details see:
https://www.knot-dns.cz/2020-05-25-version-295.html

"Bugfixes:

 Old ZSK can be withdrawn too early during a ZSK rollover if maximum
 zone TTL is computed automatically
 Server responds SERVFAIL to ANY queries on empty non-terminal nodes

Improvements:

 Also module onlinesign returns minimized responses to ANY queries
 Linking against libcap-ng can be disabled via a configure option"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2020-05-27 11:07:55 +00:00
Matthias Fischer
d73e1c75c8 knot: Update to 2.9.4
For details see:
https://www.knot-dns.cz/2020-05-05-version-294.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2020-05-18 20:20:06 +00:00
Matthias Fischer
68e83070e2 knot: Update to 2.9.2
For details see:
https://www.knot-dns.cz/2019-12-12-version-292.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-12-29 18:01:05 +00:00
Matthias Fischer
5725768496 knot: Update to 2.8.4
For details see:
https://www.knot-dns.cz/2019-09-24-version-284.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-10-08 18:35:16 +00:00
Matthias Fischer
4bb1d994b0 knot: Update to 2.8.3
For details see:
https://www.knot-dns.cz/2019-07-16-version-283.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-08-20 17:38:19 +00:00
Matthias Fischer
d52b5a4c22 knot: Update to 2.8.2
For details see:
https://www.knot-dns.cz/2019-06-05-version-282.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-07 11:12:35 +01:00
Matthias Fischer
45e4d6af99 knot: Update to 2.8.1
For details see:
https://www.knot-dns.cz/2019-04-09-version-281.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-05-07 23:49:29 +01:00
Arne Fitzenreiter
eaf004a468 knot: update to 2.8.0 and build/install only kdig
This fix compile errors on small arm boards. (cc1 internal error)

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-03-13 15:06:23 +01:00
Erik Kapfer
2397e51335 knot: Reduced version of knot with kdig only
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-02-13 11:31:37 +00:00