1. 12 Apr, 2021 1 commit
  2. 08 Apr, 2021 2 commits
  3. 07 Apr, 2021 3 commits
  4. 02 Apr, 2021 1 commit
  5. 01 Apr, 2021 1 commit
  6. 25 Mar, 2021 1 commit
  7. 22 Mar, 2021 2 commits
    • Matthijs Mekking's avatar
      Rekey immediately after rndc checkds/rollover · 82f72ae2
      Matthijs Mekking authored
      Call 'dns_zone_rekey' after a 'rndc dnssec -checkds' or 'rndc dnssec
      -rollover' command is received, because such a command may influence
      the next key event. Updating the keys immediately avoids unnecessary
      rollover delays.
      
      The kasp system test no longer needs to call 'rndc loadkeys' after
      a 'rndc dnssec -checkds' or 'rndc dnssec -rollover' command.
      82f72ae2
    • Matthijs Mekking's avatar
      Add CHANGES and notes for [#2517] · 841e90c6
      Matthijs Mekking authored
      841e90c6
  8. 20 Mar, 2021 2 commits
    • Evan Hunt's avatar
      placeholder for #2575 · c452c0a0
      Evan Hunt authored
      Issue #2575 was merged to 9.16 only as change 5603, but a placeholder
      was not added to CHANGES in the main branch. This commit adds the
      placeholder and renumbers the two subsequent changes.
      c452c0a0
    • Evan Hunt's avatar
      CHANGES · 1933bcf1
      Evan Hunt authored
      1933bcf1
  9. 19 Mar, 2021 1 commit
  10. 18 Mar, 2021 3 commits
  11. 17 Mar, 2021 1 commit
    • Matthijs Mekking's avatar
      Fix "unable to thaw dynamic kasp zone" · b518ed9f
      Matthijs Mekking authored
      Dynamic zones with dnssec-policy could not be thawed because KASP
      zones were considered always dynamic. But a dynamic KASP zone should
      also check whether updates are disabled.
      b518ed9f
  12. 16 Mar, 2021 2 commits
    • Matthijs Mekking's avatar
      Add change entry for [#2514] · c69fafdd
      Matthijs Mekking authored
      c69fafdd
    • Matthijs Mekking's avatar
      Fix a XoT crash · ee0835d9
      Matthijs Mekking authored
      The transport should also be detached when we skip a master, otherwise
      named will crash when sending a SOA query to the next master over TLS,
      because the transport must be NULL when we enter
      'dns_view_gettransport'.
      ee0835d9
  13. 15 Mar, 2021 1 commit
  14. 11 Mar, 2021 1 commit
    • Matthijs Mekking's avatar
      Fix servestale fetchlimits crash · 87591de6
      Matthijs Mekking authored
      When we query the resolver for a domain name that is in the same zone
      for which is already one or more fetches outstanding, we could
      potentially hit the fetch limits. If so, recursion fails immediately
      for the incoming query and if serve-stale is enabled, we may try to
      return a stale answer.
      
      If the resolver is also is authoritative for the parent zone (for
      example the root zone), first a delegation is found, but we first
      check the cache for a better response.
      
      Nothing is found in the cache, so we try to recurse to find the
      answer to the query.
      
      Because of fetch-limits 'dns_resolver_createfetch()' returns an error,
      which 'ns_query_recurse()' propagates to the caller,
      'query_delegation_recurse()'.
      
      Because serve-stale is enabled, 'query_usestale()' is called,
      setting 'qctx->db' to the cache db, but leaving 'qctx->version'
      untouched. Now 'query_lookup()' is called to search for stale data
      in the cache database with a non-NULL 'qctx->version'
      (which is set to a zone db versio...
      87591de6
  15. 05 Mar, 2021 1 commit
  16. 04 Mar, 2021 3 commits
  17. 25 Feb, 2021 3 commits
  18. 23 Feb, 2021 2 commits
  19. 19 Feb, 2021 1 commit
  20. 18 Feb, 2021 2 commits
  21. 17 Feb, 2021 4 commits
  22. 16 Feb, 2021 1 commit
  23. 15 Feb, 2021 1 commit