Opened 10 months ago

Closed 10 months ago

Last modified 8 months ago

#22535 closed enhancement (fixed)

bind9 bind 9.20.17

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: normal Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by Bruce Dubbs, 10 months ago

Summary: bind9 bind 9.20.16=7 → bind9 bind 9.20.17

comment:2 by Bruce Dubbs, 10 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:3 by Bruce Dubbs, 10 months ago

BIND 9.20.17

New Features

  • Add patch to detect implicit bool/int/result cast.

Detection of implicit cast from a boolean into an int, or an isc_result_t into a boolean (either in an assignement or return position).

If such pattern is found, a warning comment is added into the code (and the CI will fail) so the error can be spotted and manually

Feature Changes

  • Use atomics for CMM_{LOAD,STORE}_SHARED with ThreadSanitizer.

Upstream has removed the atomics implementation of CMM_LOAD_SHARED and CMM_STORE_SHARED as these can be used also with non-stdatomics types. As we only use the CMM api with stdatomics types, we can restore the previous behaviour to prevent ThreadSanitizer warnings.

  • Provide more information when the memory allocation fails.

Provide more information about the failure when the memory allocation fails.

  • Reduce the number of outgoing queries.

Reduces the number of outgoing queries when resolving the nameservers for delegation points. This helps the DNS resolver with cold cache resolve client queries with complex delegation chains and redirections.

Bug Fixes

  • Fix the spurious timeouts while resolving names.

Sometimes the loops in the resolving (e.g. to resolve or validate ns1.example.com we need to resolve ns1.example.com) were not properly detected leading to spurious 10 seconds delay. This has been fixed and such loops are properly detected.

  • Fix bug where zone switches from NSEC3 to NSEC after retransfer.

When a zone is re-transferred, but the zone journal on an inline-signing secondary is out of sync, the zone could fall back to using NSEC records instead of NSEC3. This has been fixed.

  • Attach socket before async streamdns_resume_processing.

Call to streamdns_resume_processing is asynchronous but the socket passed as argument is not attached when scheduling the call.

While there is no reproducible way (so far) to make the socket reference number down to 0 before streamdns_resume_processing is called, attach the socket before scheduling the call. This guard against an hypothetic case where, for some reasons, the socket refcount would reach 0, and be freed from memory when streamdns_resume_processing is called.

  • AMTRELAY type 0 presentation format handling was wrong.

RFC 8777 specifies a placeholder value of "." for the gateway field when the gateway type is 0 (no gateway). This was not being checked for nor emitted when displaying the record. This has been corrected.

Instances of this record will need the placeholder period added to them when upgrading.

  • Fix parsing bug in remote-servers with key or tls.

The :any:remote-servers clause enable the following pattern using a named server-list:

remote-servers a { 1.2.3.4; ... }; remote-servers b { a key foo; };

However, such configuration was wrongly rejected, with an "unexpected token 'foo'" error. Such configuration is now accepted.

  • Fix TLS contexts cache object usage bug in the resolver.

:iscman:named could terminate unexpectedly when reconfiguring or reloading, and if client-side TLS transport was in use (for example, when forwarding queries to a DoT server). This has been fixed.

  • Fix unitiailized pointer check on getipandkeylist.

Function named_config_getipandkeylist could, in case of error in the early code attempting to get the port or tls-port, make a pointer check on a non-initialized value. This is now fixed.

  • Standardize CHECK and RETERR macros.

previously, there were over 40 separate definitions of CHECK macros, of which most used "goto cleanup", and the rest "goto failure" or "goto out". there were another 10 definitions of RETERR, of which most were identical to CHECK, but some simply returned a result code instead of jumping to a cleanup label.

this has now been standardized throughout the code base: RETERR is for returning an error code in the case of an error, and CHECK is for jumping to a cleanup tag, which is now always called "cleanup". both macros are defined in isc/util.h. :gl:!11069

  • Adding NSEC3 opt-out records could leave invalid records in chain.

When creating an NSEC3 opt-out chain, a node in the chain could be removed too soon, causing the previous NSEC3 being unable to be found, resulting in invalid NSEC3 records to be left in the zone. This has been fixed.

comment:4 by Bruce Dubbs, 10 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

8fe71e532c Update to polkit-127.
bdf48e08d4 Update to bind and bind-utilities 9.20.17.
55b1d5f87c Update to FreeRDP-3.20.0.
43e208de7d Update to cryptsetup-2.8.2.
3ffc986104 Update to unrar-7.2.3.

comment:5 by zeckma, 10 months ago

Double checked to be sure and didn't find any security fixes in this release.

comment:6 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.