aboutsummaryrefslogtreecommitdiff
path: root/dns/dnsmasq-devel
Commit message (Collapse)AuthorAgeFilesLines
* Upgrade to release candidate #1.Matthias Andree2014-03-222-7/+6
| | | | Notes: svn path=/head/; revision=348810
* Upgrade to new upstream test release #11.Matthias Andree2014-03-102-4/+4
| | | | | | | | | | | | | | | | | | | | | Git shortlog since test release #9: Speeling. Strip DNSSEC RRs when query doesn't have DO bit set. Return INSECURE when validation fails with proved non-existent DS. Negative caching for DS records. Check that unsigned replies come from unsigned zones if --dnssec-check-uns Tidy. Fix off-by-one overwrite. Don't free blockdata for negative DS cache entries. Handle replies with no answers and no NS in validate_reply. Tweak tuning params. Don't cache secure replies which we've messsed with. Mass edit of INSECURE->BOGUS returns for server failure/bad input. Can have local DS records (trust anchors). Notes: svn path=/head/; revision=347783
* Update to new test9 release.Matthias Andree2014-02-272-4/+4
| | | | | | | | | | | | | | | | | | Relevant excerpt from git shortlog between test8 and test9: Add RFC-6605 ECDSA DNSSEC verification. Don't mess with the TTL of DNSSEC RRs. No CD in forwarded queries unless dnssec-debug for TCP too. Log BOGUS validation result when upstream sends SERVFAIL. --rev-server option. Syntactic sugar for PTR queries. Omit ECC from DNSSEC if nettle library is old. Add --servers-file option. NSEC3 validation. First pass. Check signer name in RRSIGs. An NSEC record cannot attest to its own non-existance! Notes: svn path=/head/; revision=346402
* Upgrade to test8 release, bringing these upstream fixes:Matthias Andree2014-02-122-4/+4
| | | | | | | | | | | | ee41586 Use DS records as trust anchors, not DNSKEYs. 83349b8 Further tidying of AD and DO bit handling. 7fa836e Handle validation when more one key is needed. 1633e30 Fix Byte-order botch: broke DNSSEC on big-endian platforms. c8ca33f Fix DNSSEC caching problems: incomplete RRSIG RRsets. e243c07 AD bit in queries handled as RFC6840 p5.7 Notes: svn path=/head/; revision=344016
* Move all the way to the test7 release that has other bugfixes.Matthias Andree2014-02-074-95/+4
| | | | | | | | Note the +AD flag may now be missing on the first response for a given domain, re-querying within the cache TTL would deliver it. Bug has been reported. Notes: svn path=/head/; revision=343200
* really add the promised AD flag patch.Matthias Andree2014-02-072-1/+78
| | | | | | | Pointy hat to: yours truly Notes: svn path=/head/; revision=343196
* Add Simon's patch from Git for AD flag treatment (dig ... +ad).Matthias Andree2014-02-071-0/+1
| | | | Notes: svn path=/head/; revision=343194
* Upgrade to test6, which adds DNSSEC validation and caching support.Matthias Andree2014-02-054-6/+31
| | | | | | | | Note that this requires configuration (see dnsmasq.conf.example for hints) and has a few rough edges with regard to caching. Notes: svn path=/head/; revision=342621
* Update to new upstream 2.69test3 release, with these noteworthy changes:Matthias Andree2014-01-012-5/+6
| | | | | | | | | | | | - Implement dynamic interface discovery on *BSD - Fix endless loop with some bogu-nxdomain. Another F_CONFIG botch. - Ignore ",," in dhcp-host, rather than treating it as ",0," Invent an additional .0 so we can later have 2.69rc... releases without touching PORTEPOCH. Notes: svn path=/head/; revision=338400
* Upgrade dnsmasq to new stable 2.68 release.Matthias Andree2013-12-081-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes bind-interfaces with IPv6 on FreeBSD. version 2.68 Use random addresses for DHCPv6 temporary address allocations, instead of algorithmically determined stable addresses. Fix bug which meant that the DHCPv6 DUID was not available in DHCP script runs during the lifetime of the dnsmasq process which created the DUID de-novo. Once the DUID was created and stored in the lease file and dnsmasq restarted, this bug disappeared. Fix bug introduced in 2.67 which could result in erroneous NXDOMAIN returns to CNAME queries. Fix build failures on MacOS X and openBSD. Allow subnet specifications in --auth-zone to be interface names as well as address literals. This makes it possible to configure authoritative DNS when local address ranges are dynamic and works much better than the previous work-around which exempted contructed DHCP ranges from the IP address filtering. As a consequence, that work-around is removed. Under certain circumstances, this change wil break existing configuration: if you're relying on the contructed-range exception, you need to change --auth-zone to specify the same interface as is used to construct your DHCP ranges, probably with a trailing /6 like this: --auth-zone=example.com,eth0/6 to limit the addresses to IPv6 addresses of eth0. Fix problems when advertising deleted IPv6 prefixes. If the prefix is deleted (rather than replaced), it doesn't get advertised with zero preferred time. Thanks to Tsachi for the bug report. Fix segfault with some locally configured CNAMEs. Thanks to Andrew Childs for spotting the problem. Fix memory leak on re-reading /etc/hosts and friends, introduced in 2.67. Check the arrival interface of incoming DNS and TFTP requests via IPv6, even in --bind-interfaces mode. This isn't possible for IPv4 and can generate scary warnings, but as it's always possible for IPv6 (the API always exists) then we should do it always. Tweak the rules on prefix-lengths in --dhcp-range for IPv6. The new rule is that the specified prefix length must be larger than or equal to the prefix length of the corresponding address on the local interface. Notes: svn path=/head/; revision=335916
* Upgrade to upstream -rc5, fixing binding to IPv6 interfaces withMatthias Andree2013-12-042-3/+3
| | | | | | | | | | | | | non-local addresses. Important upstream changes between -rc4 and -rc5: - Don't overwrite errno before generating message. - Garbage collect listening sockets when their address is deleted. - Only set scope_id in addresses to bind() for linklocal addresses. - Check arrival interface of IPv6 requests, even in --bind-interfaces. - Relax rules in prefix length in (IPv6) dhcp-range. Notes: svn path=/head/; revision=335607
* Update to new release candidate #4.Matthias Andree2013-11-262-3/+3
| | | | | | | | | | Upstream changes: - Add missing malloc() return-code check. - Do immediate RA when a prefix goes from old->current. - Fixes to various compiler warnings. Notes: svn path=/head/; revision=334979
* Update to new upstream release candidate #3, with three changes since RC1:Matthias Andree2013-11-252-3/+3
| | | | | | | | | 2543906 Segfault with some CNAMEs. Also memory leak on reload of /etc/hosts. 241fa9c Remove arc4random, we have a good RNG and it's a portability problem. e142a83 Merge messages to .po files. Notes: svn path=/head/; revision=334903
* Update to new release candidate #1 for 2.68.Matthias Andree2013-11-212-4/+4
| | | | | | | Changes: http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2013q4/007808.html Notes: svn path=/head/; revision=334530
* Upgrade dnsmasq to new upstream release 2.67.Matthias Andree2013-10-251-0/+1
| | | | | | | | | | | Changelog: <http://www.thekelleys.org.uk/dnsmasq/CHANGELOG> Enable NLS and IPV6 options by default. Use shebangfix on files that need it. Mark dnsmasq-devel (older than release) IGNORE. Notes: svn path=/head/; revision=331639
* Upgrade to rc4, changes over rc3 (-: removed, +: added)Matthias Andree2013-10-172-3/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | REVERT: Add --force-fast-ra option. Another thanks to Uwe Schindler. NEW: + Update Spanish transalation. Thanks to Vicente Soriano. + Add --ra-param option. Thanks to Vladislav Grishenko for + inspiration on this. + Add --add-subnet configuration, to tell upstream DNS + servers where the original client is. Thanks to DNSthingy + for sponsoring this feature. + Add --quiet-dhcp, --quiet-dhcp6 and --quiet-ra. Thanks to + Kevin Darbyshire-Bryant for the initial patch. + Allow A/AAAA records created by --interface-name to be the + target of --cname. Thanks to Hadmut Danisch for the + suggestion. + Avoid treating a --dhcp-host which has an IPv6 address + as eligable for use with DHCPv4 on the grounds that it has + no address, and vice-versa. Thanks to Yury Konovalov for + spotting the problem. + Do a better job caching dangling CNAMEs. Thanks to Yves + Dorfsman for spotting the problem. Fix shebang lines of two Perl scripts. Notes: svn path=/head/; revision=330686
* Update to 2.67 release candidate #3.Matthias Andree2013-10-063-31/+22
| | | | | | | | | | | | | While here, support staging. Changelog for RC1: <http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2013q4/007572.html> Git commit log with newer rc2/rc3 tags: <http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=shortlog> Notes: svn path=/head/; revision=329632
* Add NO_STAGE all over the place in preparation for the staging support (cat: ↵Baptiste Daroussin2013-09-201-0/+1
| | | | | | | dns) Notes: svn path=/head/; revision=327719
* Mark IGNORE.Matthias Andree2013-09-041-1/+1
| | | | Notes: svn path=/head/; revision=326305
* - Remove MAKE_JOBS_SAFE variableAlex Kozlov2013-08-141-1/+0
| | | | | | | Approved by: portmgr (bdrewery) Notes: svn path=/head/; revision=324744
* - Convert USE_GETTEXT to USES (part 4)Alex Kozlov2013-04-261-1/+1
| | | | | | | Approved by: portmgr (bapt) Notes: svn path=/head/; revision=316596
* Convert dns to USES=pkgconfigBaptiste Daroussin2013-04-231-2/+2
| | | | Notes: svn path=/head/; revision=316315
* DNSMasq 2.66rc5 fixes a DHCPv6 issue where dnsmasq 2.66rc2 spoils its ownMatthias Andree2013-04-152-3/+3
| | | | | | | | | | | | | leases file for IPv6 records. The closest evidence to a changelog is the mailing list message at http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2013q2/007028.html (and a few prior messages in that same thread). PR: ports/177788 Approved by: portmgr (bdrewery) Notes: svn path=/head/; revision=315804
* Update to new upstream release candidate 2.66rc2.Matthias Andree2013-03-232-8/+4
| | | | Notes: svn path=/head/; revision=315034
* Update to new upstream release candidate #3 to 2.64.Matthias Andree2012-12-032-3/+3
| | | | | | | Feature safe: yes Notes: svn path=/head/; revision=308176
* Update to new release candidate v2.64rc1 (after portscout complaint).Matthias Andree2012-11-152-3/+3
| | | | | | | Feature safe: yes (leaf port) Notes: svn path=/head/; revision=307464
* Demote USE_PKGCONFIG to =build (was =yes).Matthias Andree2012-08-201-2/+2
| | | | Notes: svn path=/head/; revision=302829
* Update to rc6, which became the formal release.Matthias Andree2012-08-202-3/+3
| | | | Notes: svn path=/head/; revision=302827
* Update to rc3 to avoid nag questions.Matthias Andree2012-08-092-4/+3
| | | | | | | Now uses .tar.xz suffix. Notes: svn path=/head/; revision=302354
* Add new dnsmasq-devel version, for development/test/release candidate versions.Matthias Andree2012-08-076-0/+263
This port is based on dns/dnsmasq 2.62_1,1 and has been updated to 2.63rc2. Description (by Simon Kelley, the upstream maintainer): Dnsmasq is a lightweight, easy to configure DNS forwarder and DHCP server. It is designed to provide DNS and, optionally, DHCP, to a small network. It can serve the names of local machines which are not in the global DNS. The DHCP server integrates with the DNS server and allows machines with DHCP-allocated addresses to appear in the DNS with names configured either in each host or in a central configuration file. Dnsmasq supports static and dynamic DHCP leases and BOOTP/TFTP/PXE for network booting of diskless machines. Notes: svn path=/head/; revision=302262