Opened 10 months ago

Closed 10 months ago

Last modified 8 months ago

#22413 closed enhancement (fixed)

bind9 bind 9.20.16

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: normal Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Bruce Dubbs, 10 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 10 months ago

BIND 9.20.16

Feature Changes

  • Fix assertion failure from arc4random_uniform with invalid limit.

When the arc4random_uniform() is called on NetBSD with upper_bound that makes no sense statistically (0 or 1), the call crashes the calling program. Fix this by returning 0 when upper bound is < 2 as does Linux, FreeBSD and NetBSD. (Hint: System CSPRNG should never crash.)

Bug Fixes

  • Fix dnssec-keygen key collision checking for KEY rrtype keys.

The :iscman:dnssec-keygen utility program failed to detect possible Key ID collisions with the existing keys generated using the non-default -T KEY option (e.g. for SIG(0)). This has been fixed.

  • Fix shutdown INSIST in dns_dispatchmgr_getblackhole.

Previously, named could trigger an assertion in dns_dispatchmgr_getblackhole while shutting down. This has been fixed. :gl:#5525 :gl:!11162

  • Dnssec-verify now uses exit code 1 when failing due to illegal options.

Previously, dnssec-verify exited with code 0 if the options could not be parsed. This has been fixed.

  • Prevent assertion failures of dig when server is specified before the -b option.

Previously, :iscman:dig could exit with an assertion failure when the server was specified before the :option:dig -b option. This has been fixed.

  • Skip unsupported algorithms when looking for signing key.

A mix of supported and unsupported DNSSEC algorithms in the same zone could have caused validation failures. Ignore the DNSSEC keys with unsupported algorithm when looking for the signing keys.

  • Fix configuration bugs involving global defaults.

The configuration code for the max-cache-size, dnssec-validation, and response-padding options were unnecessarily complicated, and in the case of max-cache-size, buggy. These have been fixed. The optionmaps variable in configure_view() is no longer needed and has been removed.

  • Skip buffer allocations if not logging.

Currently, during IXFR we allocate a 2KB buffer for IXFR change logging regardless of the log level. This commit introduces an early check on the log level in dns_diff_print to avoid this.

Results in a speedup from 28% in the test case from issue 5442.

comment:3 by Bruce Dubbs, 10 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

1a63431597 Update to enchant-2.8.13.
5824777533 Update to cmake-4.1.3.
55aeda165e Update to bind-utilities and bind-9.20.16.
ae791f63d7 Update to xf86-input-wacom-1.2.4 (Xorg driver).
ca9af589f6 Update to wireshark-4.6.1 (Security update).

comment:4 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.