Milestone Jul 1, 2020–Aug 5, 2020
August 2020 (9.11.22, 9.11.22-S1, 9.16.6, 9.17.4)
Unstarted Issues (open and unassigned)
Ongoing Issues (open and assigned)
Completed Issues (closed)
- "geoip2" system test fails intermittently
- [CVE-2020-8624] "update-policy" rules of type "subdomain" are enforced incorrectly
- Add libuv version to "named -V" output
- dns_rdata_hip_next() fails to return ISC_R_NOMORE at the right time.
- Bind not handling interfaces changes correctly when listen-on-v6 any specified
- [CVE-2020-8623] A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
- 'rndc dnstap --roll' fix was incomplete
- Windows crashes with netmgr-based statschannel
- BIND ARM incorrectly documents the processing of forwarders (still has the pre 9.3.0 explanation)
- [CVE-2020-8622] A truncated TSIG response can lead to an assertion failure
- README.md -- typo
- A single hung outgoing TCP connection causes resolution to time out with default settings
- use netmgr for statschannel
- Double unlock in bin/named/server.c
- configure call needs to be cleaned up main: gcc:centos6:amd64
- Statschannel system test failed at setup stage.
- Unchecked returns of inet_pton in geoip_test.c
- Add assertion check to silence dereference before NULL check in tsig_test.c
- Off-by-one error in dns_rdatatype_attributes?
- Potential NULL pointer dereference (9.11) in dnstap.c
- Update ISC logo in documentation
- Coverity reports CHECKED_RETURN defects in keymgr
- Coverity is reporting double unlock.
- Remove redundant listener != NULL check
- Add a regular "make dist" job to CI
- ddns-confgen should be an alias to tsig-keygen, not the other way around
- [CVE-2020-8621] Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
- [CVE-2020-8620]: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c
- gssapictx.c:681:10: error: implicit declaration of function 'gsskrb5_register_acceptor_identity' on illumos
- netscope.c:23:50: error: unused parameter 'addr' when HAVE_IF_NAMETOINDEX undefined on illumos
- check.c:1576:37: error: expected identifier before numeric constant on illumos
- Cleanup redundant non-NULL check.
- Bad isc_mem_put size.
- 'rndc dnstap --roll' with too big a argument (>128) can cause a buffer overflow.
- bad output rndc dnssec -status on Windows
- LMDB 0.9.26 will break "rndc reconfig" (+ other LMDB issues)
- Don't include RRsets with TTL=0 in when preserving cache content for use by the serve-stale feature
- Resizing (growing) of cache hash tables causes delays in processing of client queries
- convert rndc and the command channel to use netmgr
- Drop use of "$FEATURETEST --have-dlopen"
- Observed stats underflow in multiple stats
- Serve-stale feature is not operationally useful - some suggestions for making it better
- RPZ wildcard passthru ignored
- ThreadSanitizer: data race lib/dns/rbtdb.c:1545 in mark_header_stale and check_stale_header
- always check return from isc_refcount_decrement
- system tests fail with new /etc/bind.keys installed
- Drop $SYSTEMTESTTOP from bin/tests/system/
- named assertion failed in interfacemgr.c on FreeBSD 12.1
- Release Checklist for BIND 9.11.22, BIND 9.11.22-S1, BIND 9.16.6, BIND 9.17.4