summaryrefslogtreecommitdiff
path: root/doc
diff options
context:
space:
mode:
authorCy Schubert <cy@FreeBSD.org>2020-12-08 21:23:03 +0000
committerCy Schubert <cy@FreeBSD.org>2020-12-08 21:23:03 +0000
commitc1dbcbf2d10cd99864ab0eb44358d9875ba0c0a5 (patch)
tree8cbca8d9dc814933d2bc59b6623b792b549aac6b /doc
parent4cb89f2eee3bb358f0491932ab0498b5319f4229 (diff)
Notes
Diffstat (limited to 'doc')
-rw-r--r--doc/Changelog163
-rw-r--r--doc/README2
-rw-r--r--doc/example.conf.in11
-rw-r--r--doc/libunbound.3.in4
-rw-r--r--doc/unbound-anchor.8.in2
-rw-r--r--doc/unbound-checkconf.8.in2
-rw-r--r--doc/unbound-control.8.in2
-rw-r--r--doc/unbound-host.1.in2
-rw-r--r--doc/unbound.8.in4
-rw-r--r--doc/unbound.conf.5.in35
10 files changed, 207 insertions, 20 deletions
diff --git a/doc/Changelog b/doc/Changelog
index 87f796398993..1622dd2b5e27 100644
--- a/doc/Changelog
+++ b/doc/Changelog
@@ -1,3 +1,166 @@
+30 November 2020: Wouter
+ - Fix assertion failure on double callback when iterator loses
+ interest in query at head of line that then has the tcp stream
+ not kept for reuse.
+ - tag for the 1.13.0rc4 release.
+
+27 November 2020: Wouter
+ - Fix compile warning for type cast in http2_submit_dns_response.
+ - Fix when use free buffer to initialize rbtree for stream reuse.
+ - Fix compile warnings for windows.
+ - Fix compile warnings in rpz initialization.
+ - Fix contrib/metrics.awk for FreeBSD awk compatibility.
+ - tag for the 1.13.0rc3 release.
+
+26 November 2020: Wouter
+ - Fix to omit UDP receive errors from log, if verbosity low.
+ These happen because of udp-connect.
+ - For #352: contrib/metrics.awk for Prometheus style metrics output.
+ - Fix that after failed read, the readagain cannot activate.
+ - Clear readagain upon decommission of pending tcp structure.
+
+25 November 2020: Wouter
+ - with udp-connect ignore connection refused with UDP timeouts.
+ - Fix udp-connect on FreeBSD, do send calls on connected UDP socket.
+ - Better fix for reuse tree comparison for is-tls sockets. Where
+ the tree key identity is preserved after cleanup of the TLS state.
+ - Remove debug commands from reuse tests.
+ - Fix memory leak for edns client tag opcode config element.
+ - Attempt fix for libevent state in tcp reuse cases after a packet
+ is written.
+ - Fix readagain and writeagain callback functions for comm point
+ cleanup.
+ - tag for the 1.13.0rc2 release.
+
+24 November 2020: Wouter
+ - Merge PR #283 : Stream reuse. This implements upstream stream
+ reuse for performing several queries over the same TCP or TLS
+ channel.
+ - set version of main branch to 1.13.0 for upcoming release.
+ - iana portlist updated.
+ - Fix one port unit test for udp-connect.
+ - tag for the 1.13.0rc1 release.
+ - Fix crash when TLS connection is closed prematurely, when
+ reuse tree comparison is not properly identical to insertion.
+ - Fix padding of struct regional for 32bit systems.
+
+23 November 2020: George
+ - Merge PR #313 from Ralph Dolmans: Replace edns-client-tag with
+ edns-client-string option.
+
+23 November 2020: Wouter
+ - Merge #351 from dvzrv: Add AF_NETLINK to set of allowed socket
+ address families.
+ - Fix #350: with the AF_NETLINK permission, to fix 1.12.0 error:
+ failed to list interfaces: getifaddrs: Address family not
+ supported by protocol.
+ - Fix #347: IP_DONTFRAG broken on Apple xcode 12.2.
+ - Option to toggle udp-connect, default is enabled.
+ - Fix for #303 CVE-2020-28935 : Fix that symlink does not interfere
+ with chown of pidfile.
+ - Further fix for it and retvalue 0 fix for it.
+
+12 November 2020: Wouter
+ - Fix to connect() to UDP destinations, default turned on,
+ this lowers vulnerability to ICMP side channels.
+ - Retry for interfaces with unused ports if possible.
+
+10 November 2020: Wouter
+ - Fix #341: fixing a possible memory leak.
+ - Fix memory leak after fix for possible memory leak failure.
+ - Fix #343: Fail to build --with-libnghttp2 with error: 'SSIZE_MAX'
+ undeclared.
+
+27 October 2020: Wouter
+ - In man page note that tls-cert-bundle is read before permission
+ drop and chroot.
+
+22 October 2020: Wouter
+ - Fix #333: Unbound Segmentation Fault w/ log_info Functions From
+ Python Mod.
+ - Fix that minimal-responses does not remove addresses from a priming
+ query response.
+
+21 October 2020: George
+ - Fix #327: net/if.h check fails on some darwin versions; contribution by
+ Joshua Root.
+ - Fix #320: potential memory corruption due to size miscomputation upton
+ custom region alloc init.
+
+21 October 2020: Wouter
+ - Merge PR #228 : infra-keep-probing option to probe hosts that are
+ down. Add infra-keep-probing: yes option. Hosts that are down are
+ probed more frequently.
+ With the option turned on, it probes about every 120 seconds,
+ eventually after exponential backoff, and that keeps that way. If
+ traffic keeps up for the domain. It probes with one at a time, eg.
+ one query is allowed to probe, other queries within that 120 second
+ interval are turned away.
+
+19 October 2020: George
+ - Merge PR #324 from James Renken: Add modern X.509v3 extensions to
+ unbound-control TLS certificates.
+ - Fix for PR #324 to attach the x509v3 extensions to the client
+ certificate.
+
+19 October 2020: Ralph
+ - local-zone regional allocations outside of chunk
+
+19 October 2020: Wouter
+ - Fix that http settings have colon in set_option, for
+ http-endpoint, http-max-streams, http-query-buffer-size,
+ http-response-buffer-size, and http-nodelay.
+ - Fix memory leak of https port string when reading config.
+ - Fix #330: [Feature request] Add unencrypted DNS over HTTPS support.
+ This adds the option http-notls-downstream: yesno to change that,
+ and the dohclient test code has the -n option.
+ - Fix python documentation warning on functions.rst inplace_cb_reply.
+ - Fix dnstap test to wait for log timer to see if queries are logged.
+ - Log ip address when http session recv fails, eg. due to tls fail.
+ - Fix to set the tcp handler event toggle flag back to default when
+ the handler structure is reused.
+ - Clean the fix for out of order TCP processing limits on number
+ of queries. It was tested to work.
+
+16 October 2020: Wouter
+ - Fix that the out of order TCP processing does not limit the
+ number of outstanding queries over a connection.
+
+15 October 2020: George
+ - Fix that if there are reply callbacks for the given rcode, those
+ are called per reply and a new message created if that was modified
+ by the call.
+ - Pass the comm_reply information to the inplace_cb_reply* functions
+ during the mesh state and update the documentation on that.
+
+15 October 2020: Wouter
+ - Merge PR #326 from netblue30: DoH: implement content-length
+ header field
+ - DoH content length, simplify code, remove declaration after
+ statement and fix cast warning.
+
+14 October 2020: Wouter
+ - Fix for python reply callback to see mesh state reply_list member,
+ it only removes it briefly for the commpoint call so that it does
+ not drop it and attempt to modify the reply list during reply.
+ - Fix that if there are on reply callbacks, those are called per
+ reply and a new message created if that was modified by the call.
+ - Free up auth zone parse region after use for lookup of host
+
+13 October 2020: Wouter
+ - Fix #323: unbound testsuite fails on mock build in systemd-nspawn
+ if systemd support is build.
+
+9 October 2020: Wouter
+ - Fix dnstap socket and the chroot not applied properly to the dnstap
+ socket path.
+ - Fix warning in libnss compile, nss_buf2dsa is not used without DSA.
+
+8 October 2020: Wouter
+ - Tag for 1.12.0 release.
+ - Current repo is version 1.12.1 in development.
+ - Fix #319: potential memory leak on config failure, in rpz config.
+
1 October 2020: Wouter
- Current repo is version 1.12.0 for release. Tag for 1.12.0rc1.
diff --git a/doc/README b/doc/README
index c6ff31a6fac3..e864bb188e33 100644
--- a/doc/README
+++ b/doc/README
@@ -1,4 +1,4 @@
-README for Unbound 1.12.0
+README for Unbound 1.13.0
Copyright 2007 NLnet Labs
http://unbound.net
diff --git a/doc/example.conf.in b/doc/example.conf.in
index 2fe9a2c7e7a7..82ccaa4dd9f9 100644
--- a/doc/example.conf.in
+++ b/doc/example.conf.in
@@ -1,7 +1,7 @@
#
# Example configuration file.
#
-# See unbound.conf(5) man page, version 1.12.0.
+# See unbound.conf(5) man page, version 1.13.0.
#
# this is a comment.
@@ -161,6 +161,9 @@ server:
# msec to wait before close of port on timeout UDP. 0 disables.
# delay-close: 0
+ # perform connect for UDP sockets to mitigate ICMP side channel.
+ # udp-connect: yes
+
# msec for waiting for an unknown server to reply. Increase if you
# are behind a slow satellite link, to eg. 1128.
# unknown-server-time-limit: 376
@@ -192,6 +195,9 @@ server:
# minimum wait time for responses, increase if uplink is long. In msec.
# infra-cache-min-rtt: 50
+ # enable to make server probe down hosts more frequently.
+ # infra-keep-probing: no
+
# the number of slabs to use for the Infrastructure cache.
# the number of slabs must be a power of 2.
# more slabs reduce lock contention, but fragment memory usage.
@@ -788,6 +794,9 @@ server:
# service.
# http-nodelay: yes
+ # Disable TLS for DNS-over-HTTP downstream service.
+ # http-notls-downstream: no
+
# DNS64 prefix. Must be specified when DNS64 is use.
# Enable dns64 in module-config. Used to synthesize IPv6 from IPv4.
# dns64-prefix: 64:ff9b::0/96
diff --git a/doc/libunbound.3.in b/doc/libunbound.3.in
index 34778ee5c09e..80f7335be05e 100644
--- a/doc/libunbound.3.in
+++ b/doc/libunbound.3.in
@@ -1,4 +1,4 @@
-.TH "libunbound" "3" "Oct 8, 2020" "NLnet Labs" "unbound 1.12.0"
+.TH "libunbound" "3" "Dec 3, 2020" "NLnet Labs" "unbound 1.13.0"
.\"
.\" libunbound.3 -- unbound library functions manual
.\"
@@ -44,7 +44,7 @@
.B ub_ctx_zone_remove,
.B ub_ctx_data_add,
.B ub_ctx_data_remove
-\- Unbound DNS validating resolver 1.12.0 functions.
+\- Unbound DNS validating resolver 1.13.0 functions.
.SH "SYNOPSIS"
.B #include <unbound.h>
.LP
diff --git a/doc/unbound-anchor.8.in b/doc/unbound-anchor.8.in
index 21f12ebeff1c..564420da04a7 100644
--- a/doc/unbound-anchor.8.in
+++ b/doc/unbound-anchor.8.in
@@ -1,4 +1,4 @@
-.TH "unbound-anchor" "8" "Oct 8, 2020" "NLnet Labs" "unbound 1.12.0"
+.TH "unbound-anchor" "8" "Dec 3, 2020" "NLnet Labs" "unbound 1.13.0"
.\"
.\" unbound-anchor.8 -- unbound anchor maintenance utility manual
.\"
diff --git a/doc/unbound-checkconf.8.in b/doc/unbound-checkconf.8.in
index a7389376599a..ab22ad0b676e 100644
--- a/doc/unbound-checkconf.8.in
+++ b/doc/unbound-checkconf.8.in
@@ -1,4 +1,4 @@
-.TH "unbound-checkconf" "8" "Oct 8, 2020" "NLnet Labs" "unbound 1.12.0"
+.TH "unbound-checkconf" "8" "Dec 3, 2020" "NLnet Labs" "unbound 1.13.0"
.\"
.\" unbound-checkconf.8 -- unbound configuration checker manual
.\"
diff --git a/doc/unbound-control.8.in b/doc/unbound-control.8.in
index f82b62d3d9b6..f63a2f49cee4 100644
--- a/doc/unbound-control.8.in
+++ b/doc/unbound-control.8.in
@@ -1,4 +1,4 @@
-.TH "unbound-control" "8" "Oct 8, 2020" "NLnet Labs" "unbound 1.12.0"
+.TH "unbound-control" "8" "Dec 3, 2020" "NLnet Labs" "unbound 1.13.0"
.\"
.\" unbound-control.8 -- unbound remote control manual
.\"
diff --git a/doc/unbound-host.1.in b/doc/unbound-host.1.in
index d3b502d92657..e0cc704d39df 100644
--- a/doc/unbound-host.1.in
+++ b/doc/unbound-host.1.in
@@ -1,4 +1,4 @@
-.TH "unbound\-host" "1" "Oct 8, 2020" "NLnet Labs" "unbound 1.12.0"
+.TH "unbound\-host" "1" "Dec 3, 2020" "NLnet Labs" "unbound 1.13.0"
.\"
.\" unbound-host.1 -- unbound DNS lookup utility
.\"
diff --git a/doc/unbound.8.in b/doc/unbound.8.in
index 44a9879e5872..c012e379eb40 100644
--- a/doc/unbound.8.in
+++ b/doc/unbound.8.in
@@ -1,4 +1,4 @@
-.TH "unbound" "8" "Oct 8, 2020" "NLnet Labs" "unbound 1.12.0"
+.TH "unbound" "8" "Dec 3, 2020" "NLnet Labs" "unbound 1.13.0"
.\"
.\" unbound.8 -- unbound manual
.\"
@@ -9,7 +9,7 @@
.\"
.SH "NAME"
.B unbound
-\- Unbound DNS validating resolver 1.12.0.
+\- Unbound DNS validating resolver 1.13.0.
.SH "SYNOPSIS"
.B unbound
.RB [ \-h ]
diff --git a/doc/unbound.conf.5.in b/doc/unbound.conf.5.in
index bcbc9f205333..a244eee7a70e 100644
--- a/doc/unbound.conf.5.in
+++ b/doc/unbound.conf.5.in
@@ -1,4 +1,4 @@
-.TH "unbound.conf" "5" "Oct 8, 2020" "NLnet Labs" "unbound 1.12.0"
+.TH "unbound.conf" "5" "Dec 3, 2020" "NLnet Labs" "unbound 1.13.0"
.\"
.\" unbound.conf.5 -- unbound.conf manual
.\"
@@ -274,6 +274,10 @@ eg. 1500 msec. When timeouts happen you need extra sockets, it checks
the ID and remote IP of packets, and unwanted packets are added to the
unwanted packet counter.
.TP
+.B udp\-connect: \fI<yes or no>
+Perform connect for UDP sockets that mitigates ICMP side channel leakage.
+Default is yes.
+.TP
.B unknown\-server\-time\-limit: \fI<msec>
The wait time in msec for waiting for an unknown server to reply.
Increase this if you are behind a slow satellite link, to eg. 1128.
@@ -382,6 +386,12 @@ Lower limit for dynamic retransmit timeout calculation in infrastructure
cache. Default is 50 milliseconds. Increase this value if using forwarders
needing more time to do recursive name resolution.
.TP
+.B infra\-keep\-probing: \fI<yes or no>
+If enabled the server keeps probing hosts that are down, in the one probe
+at a time regime. Default is no. Hosts that are down, eg. they did
+not respond during the one probe at a time period, are marked as down and
+it may take \fBinfra\-host\-ttl\fR time to get probed again.
+.TP
.B define\-tag: \fI<"list of tags">
Define the tags that can be used with local\-zone and access\-control.
Enclose the list between quotes ("") and put spaces between tags.
@@ -516,7 +526,8 @@ Alternate syntax for \fBtls\-port\fR.
If null or "", no file is used. Set it to the certificate bundle file,
for example "/etc/pki/tls/certs/ca\-bundle.crt". These certificates are used
for authenticating connections made to outside peers. For example auth\-zone
-urls, and also DNS over TLS connections.
+urls, and also DNS over TLS connections. It is read at start up before
+permission drop and chroot.
.TP
.B ssl\-cert\-bundle: \fI<file>
Alternate syntax for \fBtls\-cert\-bundle\fR.
@@ -587,6 +598,10 @@ megabytes or gigabytes (1024*1024 bytes in a megabyte).
Set TCP_NODELAY socket option on sockets used to provide DNS-over-HTTPS service.
Ignored if the option is not available. Default is yes.
.TP
+.B http\-notls\-downstream: \fI<yes or no>
+Disable use of TLS for the downstream DNS-over-HTTP connections. Useful for
+local back end servers. Default is no.
+.TP
.B use\-systemd: \fI<yes or no>
Enable or disable systemd socket activation.
Default is no.
@@ -1535,15 +1550,15 @@ Set the number of servers that should be used for fast server selection. Only
use the fastest specified number of servers with the fast\-server\-permil
option, that turns this on or off. The default is to use the fastest 3 servers.
.TP 5
-.B edns\-client\-tag: \fI<IP netblock> <tag data>
-Include an edns-client-tag option in queries with destination address matching
-the configured IP netblock. This configuration option can be used multiple
-times. The most specific match will be used. The tag data is configured in
-decimal format, from 0 to 65535.
+.B edns\-client\-string: \fI<IP netblock> <string>
+Include an EDNS0 option containing configured ascii string in queries with
+destination address matching the configured IP netblock. This configuration
+option can be used multiple times. The most specific match will be used.
.TP 5
-.B edns\-client\-tag\-opcode: \fI<opcode>
-EDNS0 option code for the edns-client-tag option, from 0 to 65535. Default is
-16, as assigned by IANA.
+.B edns\-client\-string\-opcode: \fI<opcode>
+EDNS0 option code for the \fIedns\-client\-string\fR option, from 0 to 65535.
+A value from the `Reserved for Local/Experimental` range (65001-65534) should
+be used. Default is 65001.
.SS "Remote Control Options"
In the
.B remote\-control: