* Extend `Rcode` & `OptCode` with `to_mnemonic_str`
The original idea was proposed by @rossmacarthur in PR #648.
I moved the match statement into the `to_mnemonic_str` to avoid the
unsafe block in @rossmacarthurs version and to implement it the same way
as the `int_enum` macro does.
* Update Changelog.
* Fix Changelog links
Now that our MSRV is past 1.85, we can switch to the 2024 edition. This
changes some minor behavior in the language and exposes new lints (both
from check and clippy). In particular, unsafe functions now require
unsafe blocks to call other unsafe functions; this is quite a nice
change as it exposes more places where safety comments are needed.
Improvements
* Implemented `core::error::Error` instead of `std::error::Error` for error
types, reducing the need for the `std` feature flag. ([#641] by [@soywod])
* Added missing `impl core::Error for ParseError`. ([#650] by [@soywod])
Bug fixes
* Added a length check when parsing open-ended record types like
`Dnskey<_>` which are supposed to never be too large. ([#664])
* Detect when an attempt is made to create a
`dnssec::sign::records::Rrset` with records that have different TTLs.
Unfortuantely error handling is poor so the code currently panics. At
least this prevents bad signatures but the error handling needs to be
fixed later. ([#660])
Unstable features
* `unstable-crypto`:
* Added key generation and signing for RSASHA512. ([#659])
The doc-comment on the Update Lease option mentioned a previous
draft standard that had since expired. RFC 9664 has been
standardized and now gives official meaning to EDNS(0) option,
and the comment is now updated to reflect that.
This PR adds checks to the parse functions of open-ended RDATA types to
make sure they will not exceed the maximum RDATA length of 65,535 bytes.
Specifically, these checks are added to all types that return an
error-result of LongRecordData in their new function. I hope that covers
all such types.
* Added pipeline check for `cargo doc`
* Added clarifications for `new::base::name::RevName`
* Added example usage for `new::base::Record` and `new::base::name`
* Cleaned up documentation including warnings
I noticed this in <https://github.com/NLnetLabs/daemonbase/pull/21>,
where I had copied 'domain's CI workflow. It has an example that is not
mentioned in 'Cargo.toml' and thus does not have a 'required-features';
this was breaking the 'jq' extraction used in CI. I'm pre-emptively
fixing this in 'domain' to avoid strange CI failures in the future.
Breaking changes
* Added new `LimitExceeded` variant to `MessageBuilder`'s `PushError`.
([#349])
* Changed the `Resolver` and `SearchNames` traits of the stub resolver to
use lifetimes for associated types. This makes it easier to keep the stub
resolver behind an arc or other smart pointer. ([#596])
New
* Added `rdata::dnssec::Timestamp::to_system_time` to help sorting timestamps.
([#548])
* Added support for the `TLSA`, `OPENPGPKEY`, `SSHFP`, and `IPSECKEY`
record types and added presentation format support for the `SVCB`/`HTTPS`
record types. ([#569])
* Added support for the `CAA` record type. ([#434] by [@weilence])
* Added `FreezeBuilder` to the message compressors. ([#601] by
[@rossmacarthur])
* Added support for the `RP` record type. ([#620])
* Added a position counter to the zonefile parser, available via
`Zonefile::current_offset`. ([#642])
Improvements
* Excluded `moka` dependency from the `resolv` feature, reducing the number
of dependencies and compile time significantly. ([#575] by [@WhyNotHugo])
* Made various methods in `RelativeName` into const fns. ([#576] by
[@WhyNotHugo])
Bug fixes
* When parsing a Bind-style public key file, allow an optional TTL field.
([#593])
* `XfrMiddlewareService` should always support at least one concurrent XFR.
([#599])
* Fixed generating an ED448 keypair. ([#608])
Unstable features
* `unstable-crypto-sign`
* Added support for RSA/SHA-512 to openssl signer. ([#550])
* `generate` now takes `&GenerateParams`. This breaks existing uses of
`generate` ([#608])
* `unstable-server-transport`
* Return an error response when a `Service` returns a `ServiceError`.
([#390])
* Implemented `std::error::Error` for `ServiceError`. ([#570] by
[@rossmacarthur])
* Be more lenient when timing out connections while they are in a
transaction. ([#399])
* Removed defaults for type arguments to prevent intermediate types that
impl the trait from not allowing the defaults to be overridden.
([#484])
* Added commonly required bounds to the `Service` trait rather than
leaving them to the impl. ([#484])
* Removed unnecessary `?Sized` bound on `impl Service for U where U: Deref`.
([#484])
* `unstable-sign`
* keyset improvements ([#551])
* Store the algorithm and key tag of a key to be able to reject duplicate
key tags and accidental algorithm rolls.
* Store whether a key is considered available for a key roll. Rolls with
new keys that are not available are rejected.
* Added two alternative key rolls for KSK and ZSK key rolls.
* Added an algorithm roll.
* Added more operations on UnixTime.
* Added more actions
* Allow loading public keys only. ([#594])
* Added support for decoupled keys. ([#594])
* `RecordsIter::new` has been replaced with `RecordsIter::new_from_owned`.
There is a new `RecordsIter::new_from_refs` that takes a `&[&Record]]`.
This breaks existing uses of `RecordsIter? and related types. ([#614])
* `unstable-xfr`
* Various fixes and improvements. ([#507])
Other changes
* Dependency upgrades:
* [hashbrown] to 0.17, ([#633])
* [heapless] to 0.9, ([#634])
* [octseq] to 0.6, ([#634])
* [rand] to 0.10. ([#631])
- Also enhance 'FromStr' impls to parse more of the zonefile format,
for parity with the existing 'Display' impls
- Also impl conversions between 'NameBuf' and 'RevNameBuf'
- 'ring' and 'openssl' now enable a shared 'unstable-crypto-backend'
feature, which is used internally to test whether a common backend is
available.
- Examples / doc tests in 'crypto', relying on 'crypto::common', have
been moved to the submodule to avoid needing more 'cfg' magic.
- 'unstable-crypto' now enables 'std'; this requirement was previously
undetected (and the CI will be adjusted to try to catch more of these
over time), but compilation would fail without it.
- 'unstable-sign' and 'unstable-validator' now fail to compile if
'ring' and/or 'openssl' are not enabled. Previously, those modules
would remain configured out. Its status as a breaking change is
debatable, but in any case it only affects unstable features.
jiff is a popular time library which is taking over the ecosystem. It's
easier to use (as you can see from the diff) and it doesn't pull in any
dependencies. We're using jiff in other places too (e.g. Cascade), so
this change helps clean up our dependency tree.
It turns out that GitHub Actions cache entries are immutable; the
cache saving action refuses to overwrite an existing cache entry with
a particular ID. The simplest workaround, implemented here, is to add a
unique suffix to the cache entry being saved; cache restore actions will
no longer find an exact match, but GitHub falls back to using the most
recent cache entry whose key partially matches.
We store the _ideal_ dependency versions in 'Cargo.lock', which are not
necessarily compatible with our MSRV. To improve caching, we store a
'Cargo.lock' with MSRV-compatible dependency versions (while building
caches for the MSRV). We don't want to use the cached 'Cargo.lock' all
the time, as we want to test changes to 'Cargo.lock'; but those changes
are only relevant to our target Rust version, not the MSRV.
This PR updates all non-user visible dependencies.
It also makes a slight change to the CI workflow to make it compatible
with our Minimal Supported Rust Version policy.