ChangeLog 99 KB
Newer Older
1
392.	[func]*		jinmei
2 3 4 5 6 7
	libdns++: revised the (Abstract)MessageRenderer class so that it
	has a default internal buffer and the buffer can be temporarily
	switched.  The constructor interface was modified, and a new
	method setBuffer() was added.
	(Trac #1697, git 9cabc799f2bf9a3579dae7f1f5d5467c8bb1aa40)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
8 9 10
391.	[bug]*		vorner
	The long time unused configuration options of Xfrout "log_name",
	"log_file", "log_severity", "log_version" and "log_max_bytes" were
11 12 13 14
	removed, as they had no effect (Xfrout uses the global logging
	framework).  However, if you have them set, you need to remove
	them from the configuration file or the configuration will be
	rejected.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
15 16
	(Trac #1090, git ef1eba02e4cf550e48e7318702cff6d67c1ec82e)

17 18
bind10-devel-20120301 released on March 1, 2012

Jeremy C. Reed's avatar
Jeremy C. Reed committed
19 20 21 22
390.	[bug]		vorner
	The UDP IPv6 packets are now correctly fragmented for maximum
	guaranteed MTU, so they won't get lost because being too large
	for some hop.
23
	(Trac #1534, git ff013364643f9bfa736b2d23fec39ac35872d6ad)
24

Jeremy C. Reed's avatar
Jeremy C. Reed committed
25 26 27 28 29
389.	[func]*		vorner
	Xfrout now uses the global TSIG keyring, instead of its own. This
	means the keys need to be set only once (in tsig_keys/keys).
	However, the old configuration of Xfrout/tsig_keys need to be
	removed for Xfrout to work.
30
	(Trac #1643, git 5a7953933a49a0ddd4ee1feaddc908cd2285522d)
31

32 33 34
388.	[func]		jreed
	Use prefix "sockcreator-" for the private temporary directory
	used for b10-sockcreator communication.
Jeremy C. Reed's avatar
Jeremy C. Reed committed
35
	(git b98523c1260637cb33436964dc18e9763622a242)
36

Mukund Sivaraman's avatar
Mukund Sivaraman committed
37 38 39 40 41
387.	[build]		muks
	Accept a --without-werror configure switch so that some builders can
	disable the use of -Werror in CFLAGS when building.
	(Trac #1671, git 8684a411d7718a71ad9fb616f56b26436c4f03e5)

42 43 44 45 46 47 48
386.	[bug]		jelte
	Upon initial sqlite3 database creation, the 'diffs' table is now
	always created. This already happened most of the time, but there
	are a few cases where it was skipped, resulting in potential errors
	in xfrout later.
	(Trac #1717, git 30d7686cb6e2fa64866c983e0cfb7b8fabedc7a2)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
49 50 51 52 53 54 55 56 57 58 59
385.	[bug]		jinmei
	libdns++: masterLoad() didn't accept comments placed at the end of
	an RR.  Due to this the in-memory data source cannot load a master
	file for a signed zone even if it's preprocessed with BIND 9's
	named-compilezone.
	Note: this fix is considered temporary and still only accepts some
	limited form of such comments.  The main purpose is to allow the
	in-memory data source to load any signed or unsigned zone files as
	long as they are at least normalized with named-compilezone.
	(Trac #1667, git 6f771b28eea25c693fe93a0e2379af924464a562)

60 61 62
384.	[func]		jinmei, jelte, vorner, haikuo, kevin
	b10-auth now supports NSEC3-signed zones in the in-memory data
	source.
63 64
	(Trac #1580, #1581, #1582, #1583, #1584, #1585, #1587, and
	other related changes to the in-memory data source)
65

JINMEI Tatuya's avatar
JINMEI Tatuya committed
66
383.	[build]		jinmei
67 68 69
	Fixed build failure on MacOS 10.7 (Lion) due to the use of
	IPV6_PKTINFO; the OS requires a special definition to make it
	visible to the compiler.
JINMEI Tatuya's avatar
JINMEI Tatuya committed
70 71 72
	(Trac #1633, git 19ba70c7cc3da462c70e8c4f74b321b8daad0100)

382.	[func]		jelte
Jelte Jansen's avatar
Jelte Jansen committed
73
	b10-auth now also experimentally supports statistics counters of
Jeremy C. Reed's avatar
Jeremy C. Reed committed
74
	the rcode responses it sends. The counters can be shown as
Jelte Jansen's avatar
Jelte Jansen committed
75 76 77 78 79
	rcode.<code name>, where code name is the lowercase textual
	representation of the rcode (e.g. "noerror", "formerr", etc.).
	Same note applies as for opcodes, see changelog entry 364.
	(Trac #1613, git e98da500d7b02e11347431a74f2efce5a7d622aa)

Jelte Jansen's avatar
Jelte Jansen committed
80
381.	[bug]		jinmei
Jelte Jansen's avatar
Jelte Jansen committed
81
	b10-auth: honor the DNSSEC DO bit in the new query handler.
Jelte Jansen's avatar
Jelte Jansen committed
82 83
	(Trac #1695, git 61f4da5053c6a79fbc162fb16f195cdf8f94df64)

84 85 86 87 88 89
380.	[bug]		jinmei
	libdns++: miscellaneous bug fixes for the NSECPARAM RDATA
	implementation, including incorrect handling for empty salt and
	incorrect comparison logic.
	(Trac #1638, git 966c129cc3c538841421f1e554167d33ef9bdf25)

Jelte Jansen's avatar
Jelte Jansen committed
90 91 92 93 94 95 96 97 98 99 100
379.	[bug]		jelte
	Configuration commands in bindctl now check for list indices if
	the 'identifier' argument points to a child element of a list
	item. Previously, it was possible to 'get' non-existent values
	by leaving out the index, e.g. "config show Auth/listen_on/port,
	which should be config show Auth/listen_on[<index>]/port, since
	Auth/listen_on is a list. The command without an index will now
	show an error. It is still possible to show/set the entire list
	("config show Auth/listen_on").
	(Trac #1649, git 003ca8597c8d0eb558b1819dbee203fda346ba77)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
101
378.	[func]		vorner
102
	It is possible to start authoritative server or resolver in multiple
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
103 104 105 106
	instances, to use more than one core. Configuration is described in
	the guide.
	(Trac #1596, git 17f7af0d8a42a0a67a2aade5bc269533efeb840a)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
107 108 109 110 111 112 113
377.	[bug]		jinmei
	libdns++: miscellaneous bug fixes for the NSEC and NSEC3 RDATA
	implementation, including a crash in NSEC3::toText() for some RR
	types, incorrect handling of empty NSEC3 salt, and incorrect
	comparison logic in NSEC3::compare().
	(Trac #1641, git 28ba8bd71ae4d100cb250fd8d99d80a17a6323a2)

114
376.	[bug]		jinmei, vorner
JINMEI Tatuya's avatar
JINMEI Tatuya committed
115 116 117 118 119 120 121 122
	The new query handling module of b10-auth did not handle type DS
	query correctly: It didn't look for it in the parent zone, and
	it incorrectly returned a DS from the child zone if it
	happened to exist there.  Both were corrected, and it now also
	handles the case of having authority for the child and a grand
	ancestor.
	(Trac #1570, git 2858b2098a10a8cc2d34bf87463ace0629d3670e)

123
375.	[func]		jelte
Jeremy C. Reed's avatar
Jeremy C. Reed committed
124 125 126 127 128
	Modules now inform the system when they are stopping. As a result,
	they are removed from the 'active modules' list in bindctl, which
	can then inform the user directly when it tries to send them a
	command or configuration update.  Previously this would result
	in a 'not responding' error instead of 'not running'.
Jelte Jansen's avatar
Jelte Jansen committed
129 130
	(Trac #640, git 17e78fa1bb1227340aa9815e91ed5c50d174425d)

131
374.	[func]*		stephen
132 133 134 135 136
	Alter RRsetPtr and ConstRRsetPtr to point to AbstractRRset (instead
	of RRset) to allow for specialised implementations of RRsets in
	data sources.
	(Trac #1604, git 3071211d2c537150a691120b0a5ce2b18d010239)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
137 138 139 140 141
373.	[bug]		jinmei
	libdatasrc: the in-memory data source incorrectly rejected loading
	a zone containing a CNAME RR with RRSIG and/or NSEC.
	(Trac #1551, git 76f823d42af55ce3f30a0d741fc9297c211d8b38)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
142 143
372.	[func]		vorner
	When the allocation of a socket fails for a different reason than the
JINMEI Tatuya's avatar
JINMEI Tatuya committed
144 145
	socket not being provided by the OS, the b10-auth and b10-resolver
	abort, as the system might be in inconsistent state after such error.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
146 147
	(Trac #1543, git 49ac4659f15c443e483922bf9c4f2de982bae25d)

Jelte Jansen's avatar
Jelte Jansen committed
148 149 150 151 152
371.	[bug]		jelte
	The new query handling module of b10-auth (currently only used with
	the in-memory data source) now correctly includes the DS record (or
	the denial of its existence if NSEC is used) when returning a
	delegation from a signed zone.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
153
	(Trac #1573, git bd7a3ac98177573263950303d4b2ea7400781d0f)
Jelte Jansen's avatar
Jelte Jansen committed
154

JINMEI Tatuya's avatar
JINMEI Tatuya committed
155 156 157 158 159 160 161 162
370.	[func]		jinmei
	libdns++: a new class NSEC3Hash was introduced as a utility for
	calculating NSEC3 hashes for various purposes.  Python binding was
	provided, too.  Also fixed a small bug in the NSEC3PARAM RDATA
	implementation that empty salt in text representation was
	rejected.
	(Trac #1575, git 2c421b58e810028b303d328e4e2f5b74ea124839)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
163
369.	[func]		vorner
Jeremy C. Reed's avatar
Jeremy C. Reed committed
164 165 166 167 168
	The SocketRequestor provides more information about what error
	happened when it throws, by using subclasses of the original
	exception. This way a user not interested in the difference can
	still use the original exception, while it can be recognized if
	necessary.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
169 170
	(Trac #1542, git 2080e0316a339fa3cadea00e10b1ec4bc322ada0)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
171 172 173 174 175 176 177 178 179
368.	[func]*		jinmei
	libdatasrc: the interface of ZoneFinder() was changed: WILDCARD
	related result codes were deprecated and removed, and the
	corresponding information is now provided via a separate accessor
	method on FindResult.  Other separate FindResult methods will
	also tell the caller whether the zone is signed with NSEC or NSEC3
	(when necessary and applicable).
	(Trac #1611, git c175c9c06034b4118e0dfdbccd532c2ebd4ba7e8)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
180 181 182 183 184 185 186
367.	[bug]		jinmei
	libdatasrc: in-memory data source could incorrectly reject to load
	zones containing RRSIG records.  For example, it didn't allow
	RRSIG that covers a CNAME RR.  This fix also makes sure find()
	will return RRsets with RRSIGs if they are signed.
	(Trac #1614, git e8241ea5a4adea1b42a60ee7f2c5cfb87301734c)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
187 188
366.	[bug]		vorner
	Fixed problem where a directory named "io" conflicted with the python3
JINMEI Tatuya's avatar
JINMEI Tatuya committed
189 190
	standard module "io" and caused the installation to fail.  The
	offending directory has been renamed to "cio".
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
191 192
	(Trac #1561, git d81cf24b9e37773ba9a0d5061c779834ff7d62b9)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
193 194 195 196 197
365.	[bug]		jinmei
	libdatasrc: in-memory datasource incorrectly returned delegation
	for DS lookups.
	(Trac #1571, git d22e90b5ef94880183cd652e112399b3efb9bd67)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
198 199 200 201 202 203 204 205 206 207 208
364.	[func]		jinmei
	b10-auth experimentally supports statistics counters of incoming
	requests per opcode.  The counters can be (e.g.) shown as
	opcode.<code name> in the output of the bindctl "Stats show"
	command, where <code name> is lower-cased textual representation
	of opcodes ("query", "notify", etc).
	Note: This is an experimental attempt of supporting more
	statistics counters for b10-auth, and the interface and output may
	change in future versions.
	(Trac #1399, git 07206ec76e2834de35f2e1304a274865f8f8c1a5)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
209 210
bind10-devel-20120119 released on January 19, 2012

211
363.	[func]		jelte
Jeremy C. Reed's avatar
Jeremy C. Reed committed
212 213 214
	Added dummy DDNS module b10-ddns. Currently it does not
	provide any functionality, but it is a skeleton implementation
	that will be expanded later.
215 216
	(Trac #1451, git b0d0bf39fbdc29a7879315f9b8e6d602ef3afb1b)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
217
362.	[func]*		vorner
Jeremy C. Reed's avatar
Jeremy C. Reed committed
218 219 220 221
	Due to the socket creator changes, b10-auth and b10-resolver
	are no longer needed to start as root. They are started as
	the user they should be running, so they no longer have
	the -u flag for switching the user after initialization.
222 223 224 225
	Note: this change broke backward compatibility to boss component
	configuration.  If your b10-config.db contains "setuid" for
	Boss.components, you'll need to remove that entry by hand before
	starting BIND 10.
226 227
	(Trac #1508, #1509, #1510,
	git edc5b3c12eb45437361484c843794416ad86bb00)
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
228 229

361.	[func]		vorner,jelte,jinmei
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
230
	The socket creator is now used to provide sockets. It means you can
231 232
	reconfigure the ports and addresses at runtime even when the rest
	of the bind10 runs as non root user.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
233 234
	(Trac #805,#1522, git 1830215f884e3b5efda52bd4dbb120bdca863a6a)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
235 236 237 238 239
360.	[bug]		vorner
	Fixed problem where bindctl crashed when a duplicate non-string
	item was added  to a list.  This error is now properly reported.
	(Trac #1515, git a3cf5322a73e8a97b388c6f8025b92957e5d8986)

240 241 242 243 244 245 246 247
359.	[bug]		kevin
	Corrected SOA serial check in xfrout.  It now compares the SOA
	serial of an IXFR query with that of the server based serial
	number arithmetic, and replies with a single SOA record of the
	server's current version if the former is equal to or newer
	than the latter.
	(Trac #1462, git ceeb87f6d539c413ebdc66e4cf718e7eb8559c45)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
248 249 250 251 252 253 254 255 256
358.	[bug]		jinmei
	b10-resolver ignored default configuration parameters if listen_on
	failed (this can easily happen especially for a test environment
	where the run time user doesn't have root privilege), and even if
	listen_on was updated later the resolver wouldn't work correctly
	unless it's fully restarted (for example, all queries would be
	rejected due to an empty ACL).
	(Trac #1424, git 2cba8cb83cde4f34842898a848c0b1182bc20597)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
257 258 259 260 261
357.	[bug]		jinmei
	ZoneFinder::find() for database based data sources didn't
	correctly identify out-of-zone query name and could return a
	confusing result such as NXRRSET.  It now returns NXDOMAIN with an
	empty RRset.  Note: we should rather throw an exception in such a
262
	case, which should be revisited later (see Trac #1536).
JINMEI Tatuya's avatar
JINMEI Tatuya committed
263 264
	(Trac #1430, git b35797ba1a49c78246abc8f2387901f9690b328d)

Tomek Mrugalski's avatar
Tomek Mrugalski committed
265
356.	[doc]		tomek
Tomek Mrugalski's avatar
Tomek Mrugalski committed
266 267 268
	BIND10 Guide updated. It now describes DHCPv4 and DHCPv6
	components, including their overview, usage, supported standard
	and limitations. libdhcp++ is also described.
Tomek Mrugalski's avatar
Tomek Mrugalski committed
269
	(Trac #1367, git 3758ab360efe1cdf616636b76f2e0fb41f2a62a0)
Tomek Mrugalski's avatar
Tomek Mrugalski committed
270

271 272 273 274 275 276 277 278
355.	[bug]		jinmei
	Python xfrin.diff module incorrectly combined RRSIGs of different
	type covered, possibly merging different TTLs.  As a result a
	secondary server could store different RRSIGs than those at the
	primary server if it gets these records via IXFR.
	(Trac #1502, git 57b06f8cb6681f591fa63f25a053eb6f422896ef)

354.	[func]		tomek
Tomek Mrugalski's avatar
Tomek Mrugalski committed
279 280 281
	dhcp4: Support for DISCOVER and OFFER implemented. b10-dhcp4 is
	now able to offer hardcoded leases to DHCPv4 clients.
	dhcp6: Code refactored to use the same approach as dhcp4.
Tomek Mrugalski's avatar
Tomek Mrugalski committed
282
	(Trac #1230, git aac05f566c49daad4d3de35550cfaff31c124513)
Tomek Mrugalski's avatar
Tomek Mrugalski committed
283

284
353.	[func]		tomek
Tomek Mrugalski's avatar
Tomek Mrugalski committed
285
	libdhcp++: Interface detection in Linux implemented. libdhcp++
286 287 288 289
	is now able (on Linux systems) to detect available network
	interfaces, its link-layer addresses, flags and configured
	IPv4 and IPv6 addresses. Interface detection on other
	systems is planned.
Tomek Mrugalski's avatar
Tomek Mrugalski committed
290 291
	(Trac #1237, git 8a040737426aece7cc92a795f2b712d7c3407513)

292
352.	[func]		tomek
293 294 295 296 297
	libdhcp++: Transmission and reception of DHCPv4 packets is now
	implemented. Low-level hacks are not implemented for transmission
	to hosts that don't have IPv4 address yet, so currently the code
	is usable for communication with relays only, not hosts on the
	same link.
298
	(Trac #1239, #1240, git f382050248b5b7ed1881b086d89be2d9dd8fe385)
Tomek Mrugalski's avatar
Tomek Mrugalski committed
299

Jeremy C. Reed's avatar
Jeremy C. Reed committed
300
351.	[func]		fdupont
301 302
	Alpha version of DHCP benchmarking tool added.  "perfdhcp" is able to
	test both IPv4 and IPv6 servers: it can time the four-packet exchange
Jeremy C. Reed's avatar
Jeremy C. Reed committed
303 304 305
	(DORA and SARR) as well as time the initial two-packet exchange (DO
	and SA).  More information can be obtained by invoking the utility
	(in tests/tools/perfdhcp) with the "-h" flag.
306 307
	(Trac #1450, git 85083a76107ba2236732b45524ce7018eefbaf90)

308
350.	[func]*		vorner
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
309 310 311 312 313 314
	The target parameter of ZoneFinder::find is no longer present, as the
	interface was awkward. To get all the RRsets of a single domain, use
	the new findAll method (the same applies to python version, the method
	is named find_all).
	(Trac #1483,#1484, git 0020456f8d118c9f3fd6fc585757c822b79a96f6)

Dima Volodin's avatar
Dima Volodin committed
315
349.	[bug]		dvv
Jeremy C. Reed's avatar
Jeremy C. Reed committed
316 317
	resolver: If an upstream server responds with FORMERR to an EDNS
	query, try querying it without EDNS.
Dima Volodin's avatar
Dima Volodin committed
318
	(Trac #1386, git 99ad0292af284a246fff20b3702fbd7902c45418)
Dima Volodin's avatar
Dima Volodin committed
319

320 321 322
348.	[bug]		stephen
	By default the logging output stream is now flushed after each write.
	This fixes a problem seen on some systems where the log output from
Jeremy C. Reed's avatar
Jeremy C. Reed committed
323 324
	different processes was jumbled up.  Flushing can be disabled by
	setting the appropriate option in the logging configuration.
325 326
	(Trac #1405, git 2f0aa20b44604b671e6bde78815db39381e563bf)

Jelte Jansen's avatar
Jelte Jansen committed
327
347.	[bug]		jelte
Jeremy C. Reed's avatar
Jeremy C. Reed committed
328
	Fixed a bug where adding Zonemgr/secondary_zones without explicitly
Jelte Jansen's avatar
Jelte Jansen committed
329 330 331 332 333 334
	setting the class value of the added zone resulted in a cryptic
	error in bindctl ("Error: class"). It will now correctly default to
	IN if not set. This also adds better checks on the name and class
	values, and better errors if they are bad.
	(Trac #1414, git 7b122af8489acf0f28f935a19eca2c5509a3677f)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
335
346.	[build]*		jreed
336 337 338
	Renamed libdhcp to libdhcp++.
	(Trac #1446, git d394e64f4c44f16027b1e62b4ac34e054b49221d)

339
345.	[func]		tomek
Tomek Mrugalski's avatar
Tomek Mrugalski committed
340 341 342
	dhcp4: Dummy DHCPv4 component implemented. Currently it does
	nothing useful, except providing skeleton implementation that can
	be expanded in the future.
Tomek Mrugalski's avatar
Tomek Mrugalski committed
343
	(Trac #992, git d6e33479365c8f8f62ef2b9aa5548efe6b194601)
Tomek Mrugalski's avatar
Tomek Mrugalski committed
344

345
344.	[func]		y-aharen
346 347 348
	src/lib/statistics: Added statistics counter library for entire server
	items and per zone items. Also, modified b10-auth to use it. It is
	also intended to use in the other modules such as b10-resolver.
Yoshitaka Aharen's avatar
Yoshitaka Aharen committed
349
	(Trac #510, git afddaf4c5718c2a0cc31f2eee79c4e0cc625499f)
350

Jelte Jansen's avatar
Jelte Jansen committed
351 352 353 354 355
343.	[func]		jelte
	Added IXFR-out system tests, based on the first two test sets of
	http://bind10.isc.org/wiki/IxfrSystemTests.
	(Trac #1314, git 1655bed624866a766311a01214597db01b4c7cec)

356 357
342.	[bug]		stephen
	In the resolver, a FORMERR received from an upstream nameserver
Jeremy C. Reed's avatar
Jeremy C. Reed committed
358
	now results in a SERVFAIL being returned as a response to the original
359 360 361 362
	query.  Additional debug messages added to distinguish between
	different errors in packets received from upstream nameservers.
	(Trac #1383, git 9b2b249d23576c999a65d8c338e008cabe45f0c9)

363
341.	[func]		tomek
Tomek Mrugalski's avatar
Tomek Mrugalski committed
364 365
	libdhcp++: Support for handling both IPv4 and IPv6 added.
	Also added support for binding IPv4 sockets.
366 367
	(Trac #1238, git 86a4ce45115dab4d3978c36dd2dbe07edcac02ac)

Jelte Jansen's avatar
Jelte Jansen committed
368 369 370 371 372
340.	[build]		jelte
	Fixed several linker issues related to recent gcc versions, botan
	and gtest.
	(Trac #1442, git 91fb141bfb3aadfdf96f13e157a26636f6e9f9e3)

373 374 375 376 377 378 379
339.	[bug]		jinmei
	libxfr, used by b10-auth to share TCP sockets with b10-xfrout,
	incorrectly propagated ASIO specific exceptions to the application
	if the given file name was too long.  This could lead to
	unexpected shut down of b10-auth.
	(Trac #1387, git a5e9d9176e9c60ef20c0f5ef59eeb6838ed47ab2)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
380 381 382 383 384
338.	[bug]		jinmei
	b10-xfrin didn't check SOA serials of SOA and IXFR responses,
	which resulted in unnecessary transfer or unexpected IXFR
	timeouts (these issues were not overlooked but deferred to be
	fixed until #1278 was completed).  Validation on responses to SOA
385
	queries were tightened, too.
JINMEI Tatuya's avatar
JINMEI Tatuya committed
386 387
	(Trac #1299, git 6ff03bb9d631023175df99248e8cc0cda586c30a)

Tomek Mrugalski's avatar
Tomek Mrugalski committed
388
337.	[func]		tomek
389 390 391
	libdhcp++: Support for DHCPv4 option that can store a single
	address or a list of IPv4 addresses added. Support for END option
	added.
Tomek Mrugalski's avatar
Tomek Mrugalski committed
392 393
	(Trac #1350, git cc20ff993da1ddb1c6e8a98370438b45a2be9e0a)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
394
336.	[func]		jelte
Jelte Jansen's avatar
Jelte Jansen committed
395 396 397 398 399 400 401
	libdns++ (and its python wrapper) now includes a class Serial, for 
	SOA SERIAL comparison and addition. Operations on instances of this 
	class follow the specification from RFC 1982. 
	Rdata::SOA::getSerial() now returns values of this type (and not 
	uint32_t).
	(Trac #1278, git 2ae72d76c74f61a67590722c73ebbf631388acbd)

Jelte Jansen's avatar
Jelte Jansen committed
402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417
335.	[bug]*		jelte
	The DataSourceClientContainer class that dynamically loads 
	datasource backend libraries no longer provides just a .so file name 
	to its call to dlopen(), but passes it an absolute path. This means 
	that it is no longer an system implementation detail that depends on 
	[DY]LD_LIBRARY_PATH which file is chosen, should there be multiple 
	options (for instance, when test-running a new build while a 
	different version is installed).
	These loadable libraries are also no longer installed in the default 
	library path, but in a subdirectory of the libexec directory of the 
	target ($prefix/libexec/[version]/backends).
	This also removes the need to handle b10-xfin and b10-xfrout as 
	'special' hardcoded components, and they are now started as regular 
	components as dictated by the configuration of the boss process.
	(Trac #1292, git 83ce13c2d85068a1bec015361e4ef8c35590a5d0)

418 419 420 421 422 423 424 425 426
334.	[bug]		jinmei
	b10-xfrout could potentially create an overflow response message
	(exceeding the 64KB max) or could create unnecessarily small
	messages.  The former was actually unlikely to happen due to the
	effect of name compression, and the latter was marginal and at least
	shouldn't cause an interoperability problem, but these were still
	potential problems and were fixed.
	(Trac #1389, git 3fdce88046bdad392bd89ea656ec4ac3c858ca2f)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
427 428 429
333.	[bug]		dvv
	Solaris needs "-z now" to force non-lazy binding and prevent
	g++ static initialization code from deadlocking.
Dima Volodin's avatar
Dima Volodin committed
430 431
	(Trac #1439, git c789138250b33b6b08262425a08a2a0469d90433)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
432
332.	[bug]		vorner
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
433
	C++ exceptions in the isc.dns.Rdata wrapper are now converted
Jeremy C. Reed's avatar
Jeremy C. Reed committed
434
	to python ones instead of just aborting the interpreter.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
435 436
	(Trac #1407, git 5b64e839be2906b8950f5b1e42a3fadd72fca033)

437 438
bind10-devel-20111128 released on November 28, 2011

439 440 441 442
331.	[bug]		shane
	Fixed a bug in data source library where a zone with more labels
	than an out-of-bailiwick name server would cause an exception to
	be raised.
443
	(Trac #1430, git 81f62344db074bc5eea3aaf3682122fdec6451ad)
444

Jelte Jansen's avatar
Jelte Jansen committed
445 446 447
330.	[bug]		jelte
	Fixed a bug in b10-auth where it would sometimes fail because it
	tried to check for queued msgq messages before the session was
448 449
	fully running.
	(git c35d0dde3e835fc5f0a78fcfcc8b76c74bc727ca)
Jelte Jansen's avatar
Jelte Jansen committed
450

Jeremy C. Reed's avatar
Jeremy C. Reed committed
451
329.	[doc]		vorner, jreed
452 453
	Document the bind10 run control configuration in guide and
	manual page.
Jeremy C. Reed's avatar
Jeremy C. Reed committed
454 455
	(Trac #1341, git c1171699a2b501321ab54207ad26e5da2b092d63)

Jelte Jansen's avatar
Jelte Jansen committed
456 457 458 459 460
328.	[func]		jelte
	b10-auth now passes IXFR requests on to b10-xfrout, and no longer
	responds to them with NOTIMPL.
	(Trac #1390, git ab3f90da16d31fc6833d869686e07729d9b8c135)

461 462 463 464 465 466
327.	[func]		jinmei
	b10-xfrout now supports IXFR.  (Right now there is no user
	configurable parameter about this feature; b10-xfrout will
	always respond to IXFR requests according to RFC1995).
	(Trac #1371 and #1372, git 80c131f5b0763753d199b0fb9b51f10990bcd92b)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
467
326.	[build]*		jinmei
468 469 470 471 472 473
	Added a check script for the SQLite3 schema version.  It will be
	run at the beginning of 'make install', and if it detects an old
	version of schema, installation will stop.  You'll then need to
	upgrade the database file by following the error message.
	(Trac #1404, git a435f3ac50667bcb76dca44b7b5d152f45432b57)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
474 475 476 477 478 479 480 481 482
325.	[func]		jinmei
	Python isc.datasrc: added interfaces for difference management:
	DataSourceClient.get_updater() now has the 'journaling' parameter
	to enable storing diffs to the data source, and a new class
	ZoneJournalReader was introduced to retrieve them, which can be
	created by the new DataSourceClient.get_journal_reader() method.
	(Trac #1333, git 3e19362bc1ba7dc67a87768e2b172c48b32417f5,
	git 39def1d39c9543fc485eceaa5d390062edb97676)

483 484 485 486 487 488
324.	[bug]		jinmei
	Fixed reference leak in the isc.log Python module.  Most of all
	BIND 10 Python programs had memory leak (even though the pace of
	leak may be slow) due to this bug.
	(Trac #1359, git 164d651a0e4c1059c71f56b52ea87ac72b7f6c77)

489 490 491 492 493 494 495 496 497
323.	[bug]		jinmei
	b10-xfrout incorrectly skipped adding TSIG RRs to some
	intermediate responses (when TSIG is to be used for the
	responses).  While RFC2845 optionally allows to skip intermediate
	TSIGs (as long as the digest for the skipped part was included
	in a later TSIG), the underlying TSIG API doesn't support this
	mode of signing.
	(Trac #1370, git 76fb414ea5257b639ba58ee336fae9a68998b30d)

498 499 500 501 502 503 504
322.	[func]		jinmei
	datasrc: Added C++ API for retrieving difference of two versions
	of a zone.  A new ZoneJournalReader class was introduced for this
	purpose, and a corresponding factory method was added to
	DataSourceClient.
	(Trac #1332, git c1138d13b2692fa3a4f2ae1454052c866d24e654)

505 506 507 508 509 510 511 512
321.	[func]*		jinmei
	b10-xfrin now installs IXFR differences into the underlying data
	source (if it supports journaling) so that the stored differences
	can be used for subsequent IXFR-out transactions.
	Note: this is a backward incompatibility change for older sqlite3
	database files.  They need to be upgraded to have a "diffs" table.
	(Trac #1376, git 1219d81b49e51adece77dc57b5902fa1c6be1407)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
513
320.	[func]*		vorner
514 515 516
	The --brittle switch was removed from the bind10 executable.
	It didn't work after change #316 (Trac #213) and the same
	effect can be accomplished by declaring all components as core.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
517 518
	(Trac #1340, git f9224368908dd7ba16875b0d36329cf1161193f0)

519
319.	[func]		naokikambe
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
520
	b10-stats-httpd was updated. In addition of the access to all
Jeremy C. Reed's avatar
Jeremy C. Reed committed
521 522 523 524
	statistics items of all modules, the specified item or the items
	of the specified module name can be accessed.  For example, the
	URI requested by using the feature is showed as
	"/bind10/statistics/xml/Auth" or
525
	"/bind10/statistics/xml/Auth/queries.tcp". The list of all possible
Jeremy C. Reed's avatar
Jeremy C. Reed committed
526 527 528 529
	module names and all possible item names can be showed in the
	root document, whose URI is "/bind10/statistics/xml".  This change
	is not only for the XML documents but also is for the XSD and
	XSL documents.
530
	(Trac #917, git b34bf286c064d44746ec0b79e38a6177d01e6956)
531

Jeremy C. Reed's avatar
Jeremy C. Reed committed
532 533 534
318.	[func]		stephen
	Add C++ API for accessing zone difference information in
	database-based data sources.
535 536
	(Trac #1330, git 78770f52c7f1e7268d99e8bfa8c61e889813bb33)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
537 538 539 540 541
317.	[func]		vorner
	datasrc: the getUpdater method of DataSourceClient supports an
	optional 'journaling' parameter to indicate the generated updater
	to store diffs.  The database based derived class implements this
	extension.
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
542 543
	(Trac #1331, git 713160c9bed3d991a00b2ea5e7e3e7714d79625d)

Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
544
316.	[func]*		vorner
Jeremy C. Reed's avatar
Jeremy C. Reed committed
545 546 547
	The configuration of what parts of the system run is more
	flexible now.  Everything that should run must have an
	entry in Boss/components.
548
	(Trac #213, git 08e1873a3593b4fa06754654d22d99771aa388a6)
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
549

550
315.	[func]		tomek
Tomek Mrugalski's avatar
Tomek Mrugalski committed
551 552 553 554 555
	libdhcp: Support for DHCPv4 packet manipulation is now implemented.
	All fixed fields are now supported. Generic support for DHCPv4
	options is available (both parsing and assembly). There is no code
	that uses this new functionality yet, so it is not usable directly
	at this time. This code will be used by upcoming b10-dhcp4 daemon.
Tomek Mrugalski's avatar
Tomek Mrugalski committed
556 557
	(Trac #1228, git 31d5a4f66b18cca838ca1182b9f13034066427a7)

Jelte Jansen's avatar
Jelte Jansen committed
558 559 560 561 562 563 564 565 566 567
314.	[bug]		jelte
	b10-xfrin would previously initiate incoming transfers upon 
	receiving NOTIFY messages from any address (if the zone was 
	known to b10-xfrin, and using the configured address). It now 
	only starts a transfer if the source address from the NOTIFY 
	packet matches the configured master address and port. This was 
	really already fixed in release bind10-devel-20111014, but there 
	were some deferred cleanups to add.
	(Trac #1298, git 1177bfe30e17a76bea6b6447e14ae9be9e1ca8c2)

568 569 570 571 572 573 574 575 576
313.	[func]		jinmei
	datasrc: Added C++ API for adding zone differences to database
	based data sources.  It's intended to be used for the support for
	IXFR-in and dynamic update (so they can subsequently be retrieved
	for IXFR-out).  The addRecordDiff method of the DatabaseAccessor
	defines the interface, and a concrete implementation for SQLite3
	was provided.
	(Trac #1329, git 1aa233fab1d74dc776899df61181806679d14013)

Jelte Jansen's avatar
Jelte Jansen committed
577 578
312.	[func]		jelte
	Added an initial framework for doing system tests using the 
579 580 581 582
	cucumber-based BDD tool Lettuce. A number of general steps are
	included,  for instance running bind10 with specific
	configurations, sending queries, and inspecting query answers. A
	few very basic tests are included as well.
Jelte Jansen's avatar
Jelte Jansen committed
583 584
	(Trac #1290, git 6b75c128bcdcefd85c18ccb6def59e9acedd4437)

Jelte Jansen's avatar
Jelte Jansen committed
585 586 587 588 589 590
311.	[bug]		jelte
	Fixed a bug in bindctl where tab-completion for names that
	contain a hyphen resulted in unexpected behaviour, such as
	appending the already-typed part again.
	(Trac #1345, git f80ab7879cc29f875c40dde6b44e3796ac98d6da)

Jelte Jansen's avatar
Jelte Jansen committed
591 592 593 594 595 596 597
310.	[bug]		jelte
	Fixed a bug where bindctl could not set a value that is optional
	and has no default, resulting in the error that the setting
	itself was unknown. bindctl now correctly sees the setting and
	is able to set it.
	(Trac #1344, git 0e776c32330aee466073771600390ce74b959b38)

Jelte Jansen's avatar
Jelte Jansen committed
598 599 600 601 602 603
309.	[bug]		jelte
	Fixed a bug in bindctl where the removal of elements from a set
	with default values was not stored, unless the set had been
	modified in another way already.
	(Trac #1343, git 25c802dd1c30580b94345e83eeb6a168ab329a33)

604 605 606 607 608 609 610 611
308.	[build]		jelte
	The configure script will now use pkg-config for finding
	information about the Botan library. If pkg-config is unavailable,
	or unaware of Botan, it will fall back to botan-config. It will
	also use botan-config when a specific botan library directory is
	given using the '--with-botan=' flag
	(Trac #1194, git dc491833cf75ac1481ba1475795b0f266545013d)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
612
307.	[func]		vorner
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
613 614 615 616
	When zone transfer in fails with IXFR, it is retried with AXFR
	automatically.
	(Trac #1279, git cd3588c9020d0310f949bfd053c4d3a4bd84ef88)

617
306.	[bug]		stephen
618 619 620 621 622 623 624
	Boss process now waits for the configuration manager to initialize
	itself before continuing with startup.  This fixes a race condition
	whereby the Boss could start the configuration manager and then
	immediately start components that depended on that component being
	fully initialized.
	(Trac #1271, git 607cbae949553adac7e2a684fa25bda804658f61)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
625 626 627 628 629 630 631 632 633 634
305.	[bug]		jinmei
	Python isc.dns, isc.datasrc, xfrin, xfrout: fixed reference leak
	in Message.get_question(), Message.get_section(),
	RRset.get_rdata(), and DataSourceClient.get_updater().
	The leak caused severe memory leak in b10-xfrin, and (although no
	one reported it) should have caused less visible leak in
	b10-xfrout.  b10-xfrin had its own leak, which was also fixed.
	(Trac #1028, git a72886e643864bb6f86ab47b115a55e0c7f7fcad)

304.	[bug]		jelte
635 636 637 638 639
	The run_bind10.sh test script now no longer runs processes from
	an installed version of BIND 10, but will correctly use the
	build tree paths.
	(Trac #1246, git 1d43b46ab58077daaaf5cae3c6aa3e0eb76eb5d8)

640 641 642 643 644 645 646 647 648
303.	[bug]		jinmei
	Changed the installation path for the UNIX domain file used
	for the communication between b10-auth and b10-xfrout to a
	"@PACKAGE@" subdirectory (e.g. from /usr/local/var to
	/usr/local/var/bind10-devel).  This should be transparent change
	because this file is automatically created and cleaned up, but
	if the old file somehow remains, it can now be safely removed.
	(Trac #869, git 96e22f4284307b1d5f15e03837559711bb4f580c)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
649
302.	[bug]		jelte
Jelte Jansen's avatar
Jelte Jansen committed
650 651 652 653 654
	msgq no longer crashes if the remote end is closed while msgq
	tries to send data. It will now simply drop the message and close
	the connection itself.
	(Trac #1180, git 6e68b97b050e40e073f736d84b62b3e193dd870a)

655
301.	[func]		stephen
656 657 658
	Add system test for IXFR over TCP.
	(Trac #1213, git 68ee3818bcbecebf3e6789e81ea79d551a4ff3e8)

Tomek Mrugalski's avatar
Tomek Mrugalski committed
659
300.	[func]*		tomek
660 661 662 663 664 665 666
	libdhcp: DHCP packet library was implemented. Currently it handles
	packet reception, option parsing, option generation and output
	packet building. Generic and specialized classes for several
	DHCPv6 options (IA_NA, IAADDR, address-list) are available. A
	simple code was added that leverages libdhcp. It is a skeleton
	DHCPv6 server. It receives incoming SOLICIT and REQUEST messages
	and responds with proper ADVERTISE and REPLY. Note that since
667 668 669 670
	LeaseManager is not implemented, server assigns the same
	hardcoded lease for every client. This change removes existing
	DHCPv6 echo server as it was only a proof of concept code.
	(Trac #1186, git 67ea6de047d4dbd63c25fe7f03f5d5cc2452ad7d)
671

672 673 674 675 676 677 678 679 680
299.	[build]		jreed
	Do not install the libfake_session, libtestutils, or libbench
	libraries. They are used by tests within the source tree.
	Convert all test-related makefiles to build test code at
	regular make time to better work with test-driven development.
	This reverts some of #1901. (The tests are ran using "make
	check".)
	(Trac #1286, git cee641fd3d12341d6bfce5a6fbd913e3aebc1e8e)

681 682
bind10-devel-20111014 released on October 14, 2011

683 684 685 686
298.	[doc]		jreed
	Shorten README. Include plain text format of the Guide.
	(git d1897d3, git 337198f)

Dima Volodin's avatar
Dima Volodin committed
687
297.	[func]		dvv
688
	Implement the SPF rrtype according to RFC4408.
Dima Volodin's avatar
Dima Volodin committed
689 690
	(Trac #1140, git 146934075349f94ee27f23bf9ff01711b94e369e)

691
296.	[build]		jreed
692 693 694 695
	Do not install the unittest libraries. At this time, they
	are not useful without source tree (and they may or may
	not have googletest support). Also, convert several makefiles
	to build tests at "check" time and not build time.
Jeremy C. Reed's avatar
Jeremy C. Reed committed
696
	(Trac #1091, git 2adf4a90ad79754d52126e7988769580d20501c3)
697

698
295.	[bug]		jinmei
JINMEI Tatuya's avatar
JINMEI Tatuya committed
699 700 701 702 703 704 705 706
	__init__.py for isc.dns was installed in the wrong directory,
	which would now make xfrin fail to start.  It was also bad
	in that it replaced any existing __init__.py in th public
	site-packages directory.  After applying this fix You may want to
	check if the wrong init file is in the wrong place, in which
	case it should be removed.
	(Trac #1285, git af3b17472694f58b3d6a56d0baf64601b0f6a6a1)

707 708 709 710 711
294.	[func]		jelte, jinmei, vorner
	b10-xfrin now supports incoming IXFR.  See BIND 10 Guide for
	how to configure it and operational notes.
	(Trac #1212, multiple git merges)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
712
293.	[func]*		tomek
Tomek Mrugalski's avatar
Tomek Mrugalski committed
713 714 715 716 717 718 719 720 721
	b10-dhcp6: Implemented DHCPv6 echo server. It joins DHCPv6
	multicast groups and listens to incoming DHCPv6 client messages.
	Received messages are then echoed back to clients. This
	functionality is limited, but it can be used to test out client
	resiliency to unexpected messages. Note that network interface
	detection routines are not implemented yet, so interface name
	and its address must be specified in interfaces.txt.
	(Trac #878, git 3b1a604abf5709bfda7271fa94213f7d823de69d)

Dima Volodin's avatar
Dima Volodin committed
722
292.	[func]		dvv
723
	Implement the DLV rrtype according to RFC4431.
Dima Volodin's avatar
Dima Volodin committed
724
	(Trac #1144, git d267c0511a07c41cd92e3b0b9ee9bf693743a7cf)
725

Jeremy C. Reed's avatar
Jeremy C. Reed committed
726
291.	[func]		naokikambe
Naoki Kambe's avatar
Naoki Kambe committed
727 728 729 730
	Statistics items are specified by each module's spec file.
	Stats module can read these through the config manager. Stats
	module and stats httpd report statistics data and statistics
	schema by each module via both bindctl and HTTP/XML.
Jeremy C. Reed's avatar
Jeremy C. Reed committed
731 732
	(Trac #928,#929,#930,#1175,
	git 054699635affd9c9ecbe7a108d880829f3ba229e)
Naoki Kambe's avatar
Naoki Kambe committed
733

734 735 736 737 738 739 740 741
290.	[func]		jinmei
	libdns++/pydnspp: added an option parameter to the "from wire"
	methods of the Message class.  One option is defined,
	PRESERVE_ORDER, which specifies the parser to handle each RR
	separately, preserving the order, and constructs RRsets in the
	message sections so that each RRset contains only one RR.
	(Trac #1258, git c874cb056e2a5e656165f3c160e1b34ccfe8b302)

742 743
289.	[func]*		jinmei
	b10-xfrout: ACLs for xfrout can now be configured per zone basis.
744
	A per zone ACL is part of a more general zone configuration.  A
745 746 747 748 749 750 751 752 753 754 755 756 757 758 759
	quick example for configuring an ACL for zone "example.com" that
	rejects any transfer request for that zone is as follows:
	> config add Xfrout/zone_config
	> config set Xfrout/zone_config[0]/origin "example.com"
	> config add Xfrout/zone_config[0]/transfer_acl
	> config set Xfrout/zone_config[0]/transfer_acl[0] {"action": "REJECT"}
	The previous global ACL (query_acl) was renamed to transfer_acl,
	which now works as the default ACL.  Note: backward compatibility
	is not provided, so an existing configuration using query_acl
	needs to be updated by hand.
	Note: the per zone configuration framework is a temporary
	workaround.  It will eventually be redesigned as a system wide
	configuration.
	(Trac #1165, git 698176eccd5d55759fe9448b2c249717c932ac31)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
760
288.	[bug]		stephen
761 762 763 764 765 766
	Fixed problem whereby the order in which component files appeared in
	rdataclass.cc was system dependent, leading to problems on some
	systems where data types were used before the header file in which
	they were declared was included.
	(Trac #1202, git 4a605525cda67bea8c43ca8b3eae6e6749797450)

767 768 769 770 771 772 773 774
287.	[bug]*		jinmei
	Python script files for log messages (xxx_messages.py) should have
	been installed under the "isc" package.  This fix itself should
	be a transparent change without affecting existing configurations
	or other operational practices, but you may want to clean up the
	python files from the common directly (such as "site-packages").
	(Trac #1101, git 0eb576518f81c3758c7dbaa2522bd8302b1836b3)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
775
286.	[func]		ocean
776 777 778 779
	libdns++: Implement the HINFO rrtype support according to RFC1034,
	and RFC1035.
	(Trac #1112, git 12d62d54d33fbb1572a1aa3089b0d547d02924aa)

Jelte Jansen's avatar
Jelte Jansen committed
780 781 782 783 784 785
285.	[bug]		jelte
	sqlite3 data source: fixed a race condition on initial startup,
	when the database has not been initialized yet, and multiple
	processes are trying to do so, resulting in one of them failing.
	(Trac #326, git 5de6f9658f745e05361242042afd518b444d7466)

786 787 788
284.	[bug]		jerry
	b10-zonemgr: zonemgr will not terminate on empty zones, it will
	log a warning and try to do zone transfer for them.
789
	(Trac #1153, git 0a39659638fc68f60b95b102968d7d0ad75443ea)
790

Jeremy C. Reed's avatar
Jeremy C. Reed committed
791
283.	[bug]		zhanglikun
792 793 794 795 796 797
	Make stats and boss processes wait for answer messages from each
	other in block mode to avoid orphan answer messages, add an internal
	command "getstats" to boss process for getting statistics data from
	boss.
	(Trac #519, git 67d8e93028e014f644868fede3570abb28e5fb43)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
798
282.	[func]		ocean
799 800 801
	libdns++: Implement the NAPTR rrtype according to RFC2915,
	RFC2168 and RFC3403.
	(Trac #1130, git 01d8d0f13289ecdf9996d6d5d26ac0d43e30549c)
802

803 804
bind10-devel-20110819 released on August 19, 2011

805 806 807 808
281.	[func]		jelte
	Added a new type for configuration data: "named set". This allows for
	similar configuration as the current "list" type, but with strings
	instead of indices as identifiers. The intended use is for instance
809 810
	/foo/zones/example.org/bar instead of /foo/zones[2]/bar. Currently
	this new type is not in use yet.
811 812
	(Trac #926, git 06aeefc4787c82db7f5443651f099c5af47bd4d6)

813 814
280.	[func]		jerry
	libdns++: Implement the MINFO rrtype according to RFC1035.
815
	(Trac #1113, git 7a9a19d6431df02d48a7bc9de44f08d9450d3a37)
816

817 818
279.	[func]		jerry
	libdns++: Implement the AFSDB rrtype according to RFC1183.
819
	(Trac #1114, git ce052cd92cd128ea3db5a8f154bd151956c2920c)
820

821 822
278.	[doc]		jelte
	Add logging configuration documentation to the guide.
823
	(Trac #1011, git 2cc500af0929c1f268aeb6f8480bc428af70f4c4)
824

825
277.	[func]		jerry
826
	libdns++: Implement the SRV rrtype according to RFC2782.
827 828
	(Trac #1128, git 5fd94aa027828c50e63ae1073d9d6708e0a9c223)

829 830 831 832 833 834
276.	[func]		stephen
	Although the top-level loggers are named after the program (e.g.
	b10-auth, b10-resolver), allow the logger configuration to omit the
	"b10-" prefix and use just the module name.
	(Trac #1003, git a01cd4ac5a68a1749593600c0f338620511cae2d)

835 836 837 838 839 840 841 842 843 844
275.	[func]		jinmei
	Added support for TSIG key matching in ACLs.  The xfrout ACL can
	now refer to TSIG key names using the "key" attribute.  For
	example, the following specifies an ACL that allows zone transfer
	if and only if the request is signed with a TSIG of a key name
	"key.example":
	> config set Xfrout/query_acl[0] {"action": "ACCEPT", \
	                                  "key": "key.example"}
	(Trac #1104, git 9b2e89cabb6191db86f88ee717f7abc4171fa979)

845
274.	[bug]		naokikambe
846 847 848 849
	add unittests for functions xml_handler, xsd_handler and xsl_handler
	respectively to make sure their behaviors are correct, regardless of
	whether type which xml.etree.ElementTree.tostring() after Python3.2
	returns is str or byte.
850
	(Trac #1021, git 486bf91e0ecc5fbecfe637e1e75ebe373d42509b)
851

852
273.	[func]		vorner
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
853 854
	It is possible to specify ACL for the xfrout module. It is in the ACL
	configuration key and has the usual ACL syntax. It currently supports
855
	only the source address. Default ACL accepts everything.
JINMEI Tatuya's avatar
JINMEI Tatuya committed
856
	(Trac #772, git 50070c824270d5da1db0b716db73b726d458e9f7)
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
857

858 859 860 861 862
272.	[func]		jinmei
	libdns++/pydnspp: TSIG signing now handles truncated DNS messages
	(i.e. with TC bit on) with TSIG correctly.
	(Trac #910, 8e00f359e81c3cb03c5075710ead0f87f87e3220)

863 864 865 866 867 868
271.	[func]		stephen
	Default logging for unit tests changed to severity DEBUG (level 99)
	with the output routed to /dev/null.  This can be altered by setting
	the B10_LOGGER_XXX environment variables.
	(Trac #1024, git 72a0beb8dfe85b303f546d09986461886fe7a3d8)

869 870 871 872 873
270.	[func]		jinmei
	Added python bindings for ACLs using the DNS request as the
	context.  They are accessible via the isc.acl.dns module.
	(Trac #983, git c24553e21fe01121a42e2136d0a1230d75812b27)

Yoshitaka Aharen's avatar
Yoshitaka Aharen committed
874 875 876 877 878
269.	[bug]		y-aharen
	Modified IntervalTimerTest not to rely on the accuracy of the timer.
	This fix addresses occasional failure of build tests.
	(Trac #1016, git 090c4c5abac33b2b28d7bdcf3039005a014f9c5b)

879
268.	[func]		stephen
880 881 882 883
	Add environment variable to allow redirection of logging output during
	unit tests.
	(Trac #1071, git 05164f9d61006869233b498d248486b4307ea8b6)

884 885
bind10-devel-20110705 released on July 05, 2011

886 887 888 889 890 891 892
267.	[func]		tomek
	Added a dummy module for DHCP6. This module does not actually
	do anything at this point, and BIND 10 has no option for
	starting it yet. It is included as a base for further
	development.
	(Trac #990, git 4a590df96a1b1d373e87f1f56edaceccb95f267d)

893 894 895 896 897 898 899 900
266.	[func]		Multiple developers
        Convert various error messages, debugging and other output
        to the new logging interface, including for b10-resolver,
        the resolver library, the CC library, b10-auth, b10-cfgmgr,
        b10-xfrin, and b10-xfrout. This includes a lot of new
        documentation describing the new log messages.
        (Trac #738, #739, #742, #746, #759, #761, #762)

901 902 903 904 905 906 907 908 909 910 911 912 913 914
265.	[func]*		jinmei
	b10-resolver: Introduced ACL on incoming queries.  By default the
	resolver accepts queries from ::1 and 127.0.0.1 and rejects all
	others.  The ACL can be configured with bindctl via the
	"Resolver/query_acl" parameter.  For example, to accept queries
	from 192.0.2.0/24 (in addition to the default list), do this:
	> config add Resolver/query_acl
	> config set Resolver/query_acl[2]/action "ACCEPT"
	> config set Resolver/query_acl[2]/from "192.0.2.0/24"
	> config commit
	(Trac #999, git e0744372924442ec75809d3964e917680c57a2ce,
	also based on other ACL related work done by stephen and vorner)

264.	[bug]		jerry
915 916 917 918
	b10-xfrout: fixed a busy loop in its notify-out subthread.  Due to
	the loop, the thread previously woke up every 0.5 seconds throughout
	most of the lifetime of b10-xfrout, wasting the corresponding CPU
	time.
919
	(Trac #1001, git fb993ba8c52dca4a3a261e319ed095e5af8db15a)
920

921
263.	[func]		jelte
Jelte Jansen's avatar
Jelte Jansen committed
922 923 924 925
	Logging configuration can now also accept a * as a first-level
	name (e.g. '*', or '*.cache'), indicating that every module
	should use that configuration, unless overridden by an explicit
	logging configuration for that module
926
	(Trac #1004, git 0fad7d4a8557741f953eda9fed1d351a3d9dc5ef)
Jelte Jansen's avatar
Jelte Jansen committed
927

928
262.	[func]		stephen
929 930 931 932 933
	Add some initial documentation about the logging framework.
	Provide BIND 10 Messages Manual in HTML and DocBook? XML formats.
	This provides all the log message descriptions in a single document.
	A developer tool, tools/system_messages.py (available in git repo),
	was written to generate this.
934
	(Trac #1012, git 502100d7b9cd9d2300e78826a3bddd024ef38a74)
935

936
261.	[func]		stephen
937
	Add new-style logging messages to b10-auth.
938
	(Trac #738, git c021505a1a0d6ecb15a8fd1592b94baff6d115f4)
939

940
260.	[func]		stephen
941 942
	Remove comma between message identification and the message
	text in the new-style logging messages.
943
	(Trac #1031, git 1c7930a7ba19706d388e4f8dcf2a55a886b74cd2)
944

945
259.	[bug]		stephen
946 947 948
	Logging now correctly initialized in b10-auth.  Also, fixed
	bug whereby querying for "version.bind txt ch" would cause
	b10-auth to crash if BIND 10 was started with the "-v" switch.
949
	(Trac #1022,#1023, git 926a65fa08617be677a93e9e388df0f229b01067)
950

Jelte Jansen's avatar
Jelte Jansen committed
951 952 953 954
258.	[build]		jelte
	Now builds and runs with Python 3.2
	(Trac #710, git dae1d2e24f993e1eef9ab429326652f40a006dfb)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
955
257.	[bug]		y-aharen
956 957 958
	Fixed a bug an instance of IntervalTimerImpl may be destructed 
	while deadline_timer is holding the handler. This fix addresses
	occasional failure of IntervalTimerTest.destructIntervalTimer.
959
	(Trac #957, git e59c215e14b5718f62699ec32514453b983ff603)
960

961 962 963
256.	[bug]		jerry
	src/bin/xfrin: update xfrin to check TSIG before other part of
	incoming message.
964
	(Trac #955, git 261450e93af0b0406178e9ef121f81e721e0855c)
965

966 967 968
255.	[func]		zhang likun
	src/lib/cache:  remove empty code in lib/cache and the corresponding
	suppression rule in	src/cppcheck-suppress.lst.
969
	(Trac #639, git 4f714bac4547d0a025afd314c309ca5cb603e212)
970

971 972
254.	[bug]		jinmei
	b10-xfrout: failed to send notifies over IPv6 correctly.
973
	(Trac #964, git 3255c92714737bb461fb67012376788530f16e40)
974

Jeremy C. Reed's avatar
Jeremy C. Reed committed
975
253.	[func]		jelte
Jelte Jansen's avatar
Jelte Jansen committed
976 977
	Add configuration options for logging through the virtual module
	Logging.
978
	(Trac #736, git 9fa2a95177265905408c51d13c96e752b14a0824)
Jelte Jansen's avatar
Jelte Jansen committed
979

Jeremy C. Reed's avatar
Jeremy C. Reed committed
980
252.	[func]		stephen
981
	Add syslog as destination for logging.
982
	(Trac #976, git 31a30f5485859fd3df2839fc309d836e3206546e)
983

JINMEI Tatuya's avatar
JINMEI Tatuya committed
984 985 986 987 988 989 990
251.	[bug]*		jinmei
	Make sure bindctl private files are non readable to anyone except
	the owner or users in the same group.  Note that if BIND 10 is run
	with changing the user, this change means that the file owner or
	group will have to be adjusted.  Also note that this change is
	only effective for a fresh install; if these files already exist,
	their permissions must be adjusted by hand (if necessary).
991
	(Trac #870, git 461fc3cb6ebabc9f3fa5213749956467a14ebfd4)
JINMEI Tatuya's avatar
JINMEI Tatuya committed
992

Jeremy C. Reed's avatar
Jeremy C. Reed committed
993
250.	[bug]		ocean
994 995 996
	src/lib/util/encode, in some conditions, the DecodeNormalizer's
	iterator may reach the end() and when later being dereferenced
	it will cause crash on some platform.
997
	(Trac #838, git 83e33ec80c0c6485d8b116b13045b3488071770f)
998

Jeremy C. Reed's avatar
Jeremy C. Reed committed
999
249.	[func]		jerry
1000
	xfrout: add support for TSIG verification.
1001
	(Trac #816, git 3b2040e2af2f8139c1c319a2cbc429035d93f217)
1002

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1003
248.	[func]		stephen
Stephen Morris's avatar
Stephen Morris committed
1004
	Add file and stderr as destinations for logging.
1005
	(Trac #555, git 38b3546867425bd64dbc5920111a843a3330646b)
Stephen Morris's avatar
Stephen Morris committed
1006

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1007
247.	[func]		jelte
Jelte Jansen's avatar
Jelte Jansen committed
1008
	Upstream queries from the resolver now set EDNS0 buffer size.
1009
	(Trac #834, git 48e10c2530fe52c9bde6197db07674a851aa0f5d)
Jelte Jansen's avatar
Jelte Jansen committed
1010

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1011
246.	[func]		stephen
1012
	Implement logging using log4cplus (http://log4cplus.sourceforge.net)
1013
	(Trac #899, git 31d3f525dc01638aecae460cb4bc2040c9e4df10)
1014

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1015
245.	[func]		vorner
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
1016 1017 1018 1019
	Authoritative server can now sign the answers using TSIG
	(configured in tsig_keys/keys, list of strings like
	"name:<base64-secret>:sha1-hmac"). It doesn't use them for
	ACL yet, only verifies them and signs if the request is signed.
1020
	(Trac #875, git fe5e7003544e4e8f18efa7b466a65f336d8c8e4d)
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
1021

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1022
244.	[func]		stephen
1023 1024 1025 1026 1027 1028 1029
	In unit tests, allow the choice of whether unhandled exceptions are
	caught in the unit test program (and details printed) or allowed to
	propagate to the default exception handler.  See the bind10-dev thread
	https://lists.isc.org/pipermail/bind10-dev/2011-January/001867.html
	for more details.
	(Trac #542, git 1aa773d84cd6431aa1483eb34a7f4204949a610f)

1030
243.	[func]*		feng
1031
	Add optional hmac algorithm SHA224/384/512.
1032
	(Trac #782, git 77d792c9d7c1a3f95d3e6a8b721ac79002cd7db1)
Jeremy C. Reed's avatar
Jeremy C. Reed committed
1033

1034 1035
bind10-devel-20110519 released on May 19, 2011

1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046
242.	[func]		jinmei
	xfrin: added support for TSIG verify.  This change completes TSIG
	support in b10-xfrin.
	(Trac #914, git 78502c021478d97672232015b7df06a7d52e531b)

241.	[func]		jinmei
	pydnspp: added python extension for the TSIG API introduced in
	change 235.
	(Trac #905, git 081891b38f05f9a186814ab7d1cd5c572b8f777f)
	(Trac #915, git 0555ab65d0e43d03b2d40c95d833dd050eea6c23)

Jelte Jansen's avatar
Jelte Jansen committed
1047 1048 1049 1050
240.	[func]*		jelte
	Updated configuration options to Xfrin, so that you can specify
	a master address, port, and TSIG key per zone. Still only one per
	zone at this point, and TSIG keys are (currently) only specified
1051 1052 1053
	by their full string representation. This replaces the
	Xfrin/master_addr, Xfrin/master_port, and short-lived
	Xfrin/tsig_key configurations with a Xfrin/zones list.
Jelte Jansen's avatar
Jelte Jansen committed
1054 1055
	(Trac #811, git 88504d121c5e08fff947b92e698a54d24d14c375)

1056
239.	[bug]		jerry
1057
	src/bin/xfrout: If a zone doesn't have notify slaves (only has
1058 1059 1060 1061
	one apex ns record - the primary master name server) will cause
	b10-xfrout uses 100% of CPU.
	(Trac #684, git d11b5e89203a5340d4e5ca51c4c02db17c33dc1f)

zhanglikun's avatar
zhanglikun committed
1062
238.	[func]		zhang likun
1063
	Implement the simplest forwarder, which pass everything through
zhanglikun's avatar
zhanglikun committed
1064 1065 1066
	except QID, port number. The response will not be cached.
	(Trac #598_new, git 8e28187a582820857ef2dae9b13637a3881f13ba)

1067
237.	[bug]		naokikambe
Naoki Kambe's avatar
Naoki Kambe committed
1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078
	Resolved that the stats module wasn't configurable in bindctl in
	spite of its having configuration items. The configuration part
	was removed from the original spec file "stats.spec" and was
	placed in a new spec file "stats-schema.spec". Because it means
	definitions of statistics items. The command part is still
	there. Thus stats module currently has no its own configuration,
	and the items in "stats-schema.spec" are neither visible nor
	configurable through bindctl. "stats-schema.spec" is shared with
	stats module and stats-httpd module, and maybe with other
	statistical modules in future. "stats.spec" has own configuration
	and commands of stats module, if it requires.
1079
	(Trac #719, git a234b20dc6617392deb8a1e00eb0eed0ff353c0a)
1080

Jelte Jansen's avatar
Jelte Jansen committed
1081 1082 1083 1084 1085 1086
236.	[func]		jelte
	C++ client side of configuration now uses BIND10 logging system.
	It also has improved error handling when communicating with the
	rest of the system.
	(Trac #743, git 86632c12308c3ed099d75eb828f740c526dd7ec0)

1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097
235.	[func]		jinmei
	libdns++: added support for TSIG signing and verification.  It can
	be done using a newly introduced TSIGContext class.
	Note: we temporarily disabled support for truncated signature
	and modified some part of the code introduced in #226 accordingly.
	We plan to fix this pretty soon.
	(Trac #812, git ebe0c4b1e66d359227bdd1bd47395fee7b957f14)
	(Trac #871, git 7c54055c0e47c7a0e36fcfab4b47ff180c0ca8c8)
	(Trac #813, git ffa2f0672084c1f16e5784cdcdd55822f119feaa)
	(Trac #893, git 5aaa6c0f628ed7c2093ecdbac93a2c8cf6c94349)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1098
234.	[func]		jerry
1099 1100
	src/bin/xfrin: update xfrin to use TSIG. Currently it only supports
	sending a signed TSIG request or SOA request.
chenzhengzhang's avatar
chenzhengzhang committed
1101
	(Trac #815, git a892818fb13a1839c82104523cb6cb359c970e88)
1102

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1103
233.	[func]		stephen
1104 1105 1106
	Added new-style logging statements to the NSAS code.
	(Trac #745, git ceef68cd1223ae14d8412adbe18af2812ade8c2d)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1107 1108 1109 1110 1111 1112
232.	[func]		stephen
	To facilitate the writing of extended descriptions in
	message files, altered the message file format.  The message
	is now flagged with a "%" as the first non-blank character
	in the line and the lines in the extended description are
	no longer preceded by a "+".
1113 1114
	(Trac #900, git b395258c708b49a5da8d0cffcb48d83294354ba3)

Jeremy C. Reed's avatar
Jeremy C. Reed committed
1115
231.	[func]*		vorner
1116
    The logging interface changed slightly. We use
Jeremy C. Reed's avatar
Jeremy C. Reed committed
1117 1118 1119 1120 1121
	logger.foo(MESSAGE_ID).arg(bar); instead of logger.foo(MESSAGE_ID,
	bar); internally. The message definitions use '%1,%2,...'
	instead of '%s,%d', which allows us to cope better with
	mismatched placeholders and allows reordering of them in
	case of translation.
1122
	(Trac #901, git 4903410e45670b30d7283f5d69dc28c2069237d6)
Michal 'vorner' Vaner's avatar
Michal 'vorner' Vaner committed
1123

Naoki Kambe's avatar
Naoki Kambe committed
1124
230.	[bug]		naokikambe
Naoki Kambe's avatar
Naoki Kambe committed
1125 1126 1127
	Removed too repeated verbose messages in two cases of:
	 - when auth sends statistics data to stats
	 - when stats receives statistics data from other modules
1128
	(Trac #620, git 0ecb807011196eac01f281d40bc7c9d44565b364)
Naoki Kambe's avatar
Naoki Kambe committed
1129

1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142
229.	[doc]		jreed
	Add manual page for b10-host.
	(git a437d4e26b81bb07181ff35a625c540703eee845)

228.	[func]*		jreed
	The host tool is renamed to b10-host. While the utility is
	a work in progress, it is expected to now be shipped with
	tarballs. Its initial goal was to be a host(1) clone,
	rewritten in C++ from scratch and using BIND 10's libdns++.
	It now supports the -a (any), -c class, -d (verbose) switches
	and has improved output.
	(Trac #872, git d846851699d5c76937533adf9ff9d948dfd593ca)

1143 1144 1145 1146 1147 1148
227.	[build]		jreed
	Add missing libdns++ rdata files for the distribution (this
	fixes distcheck error). Change three generated libdns++
	headers to "nodist" so they aren't included in the distribution
	(they were mistakenly included in last tarball).

Jelte Jansen's avatar
Jelte Jansen committed
1149 1150 1151 1152
226.	[func]*		jelte
	Introduced an API for cryptographic operations. Currently it only
	supports HMAC, intended for use with TSIG. The current
	implementation uses Botan as the backend library.
1153 1154
	This introduces a new dependency, on Botan.  Currently only Botan
	1.8.x works; older or newer versions don't.
1155
	(Trac #781, git 9df42279a47eb617f586144dce8cce680598558a)
Jelte Jansen's avatar
Jelte Jansen committed
1156

1157
225.	[func]		naokikambe
1158
	Added the HTTP/XML interface (b10-stats-httpd) to the
1159 1160
	statistics feature in BIND 10. b10-stats-httpd is a standalone
	HTTP server and it requests statistics data to the stats
1161
	daemon (b10-stats) and sends it to HTTP clients in XML
1162 1163
	format. Items of the data collected via b10-stats-httpd
	are almost equivalent to ones which are collected via
1164 1165
	bindctl. Since it also can send XSL (Extensible Stylesheet
	Language) document and XSD (XML Schema definition) document,
1166 1167
	XML document is human-friendly to view through web browsers
	and its data types are strictly defined.
1168
	(Trac #547, git 1cbd51919237a6e65983be46e4f5a63d1877b1d3)
Naoki Kambe's avatar
Naoki Kambe committed
1169

JINMEI Tatuya's avatar
JINMEI Tatuya committed
1170 1171 1172 1173 1174 1175 1176 1177
224.	[bug]		jinmei
	b10-auth, src/lib/datasrc: inconsistency between the hot spot
	cache and actual data source could cause a crash while query
	processing.  The crash could happen, e.g., when an sqlite3 DB file
	is being updated after a zone transfer while b10-auth handles a
	query using the corresponding sqlite3 data source.
	(Trac #851, git 2463b96680bb3e9a76e50c38a4d7f1d38d810643)

JINMEI Tatuya's avatar
JINMEI Tatuya committed
1178
223.	[bug]		feng
1179 1180 1181
	If ip address or port isn't usable for name server, name
	server process won't exist and give end user chance to
	reconfigure them.
hanfeng's avatar
hanfeng committed
1182
	(Trac #775, git 572ac2cf62e18f7eb69d670b890e2a3443bfd6e7)
hanfeng's avatar
hanfeng committed
1183