Commit Graph
1600 Commits
Author SHA1 Message Date
W.C.A. Wijngaards 17bbcac979 - auth-load-thread, fix buffer free in http processing. 2026-08-11 16:50:00 +02:00
W.C.A. Wijngaards 2adbbea365 - auth-load-thread, print thread details in log at high verbosity, 8. 2026-08-11 16:23:03 +02:00
W.C.A. Wijngaards 156c00a727 Merge branch 'master' into auth-load-thread 2026-08-10 16:42:59 +02:00
W.C.A. Wijngaards d753f95956 - auth-load-thread, print time taken during auth load processing. 2026-08-10 16:42:04 +02:00
W.C.A. Wijngaards 79b84bbc91 - Fix #1482: DNS-over-QUIC doesn't work with simple config.
That fixes interface-automatic for use with doq service.
2026-07-30 08:24:42 +02:00
W.C.A. Wijngaards 9bd8df0149 - Fix to use tls-port after referral if tls-upstream is set. 2026-07-24 15:31:06 +02:00
W.C.A. Wijngaards 8f7411057f - Fix sign of comparison warning in shared ports setup. 2026-07-24 14:44:44 +02:00
W.C.A. Wijngaards ca1fe4f82a - Fix to guard access to shared ports interface array during
set up, for analyzer.
2026-07-24 14:38:46 +02:00
W.C.A. Wijngaards e183c2c506 - Fix unused variable warnings in shared_ports_fetch_random
and shared_ports_return_port when compiled without threads.
2026-07-24 14:37:17 +02:00
Petr VaganovandGitHub e6d00725c2 authzone: fix memory leak in xfer_set_masters() error path (#1480)
Added memory deallocation for the `file` and `host` fields of the
`auth_master` node in the event of a URL/allocation error, and
unlinked the partially created node from the masters list by
resetting the link that pointed to it.

Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com>
2026-07-24 12:24:49 +02:00
W.C.A. Wijngaards e597711824 - Fix lock test protect for auth zone change.
- Fix to lock shared_ports structure during initialisation.
- Fix to lock anchor structure when file is set for it in
2026-07-24 12:13:09 +02:00
W.C.A. Wijngaards 79e100a7fb - Fix #1477: respip + dns64: dns64 uses A records modified by
respip instead of original A records. Adds local-zone types
  block_a_wdata and block_aaaa_wdata, that are like block_a
  and block_aaaa, and uses local-data if present.
2026-07-24 09:29:17 +02:00
c8b3c89a39 Add new static zone type block_aaaa to suppress AAAA queries (#1433)
Following d5b9a790f lead for block_a - this would allow suppressing AAAA queries instead for sticking to IPV4.

Co-authored-by: Jisakiel <jisakiel@users.noreply.github.com>
2026-07-24 08:52:20 +02:00
W.C.A. Wijngaards a05d460e66 - Fix mesh cycle detection for configuration with respip CNAME
loop and tagged clients. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-07-23 16:28:45 +02:00
W.C.A. Wijngaards cf5e6e89a5 - Fix error in log printout in fix for CVE-2026-50248, when the
primary name is bogus.
2026-07-22 12:16:49 +02:00
W.C.A. Wijngaards 7a95bedc26 Fix conflict merge fixup. 2026-07-22 11:36:06 +02:00
W.C.A. Wijngaards 91ac449bcd Merge branch 'branch-1.25.2' 2026-07-22 11:33:54 +02:00
W.C.A. Wijngaards 84d9682dd0 - Fix CVE-2026-56444, Degradation of resolution service when
'discard-timeout' and 'serve-expired-client-timeout' are combined in
  unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report. In addition, thanks to Xin Wang, Jiapeng Li,
  and Jiajia Liu, Northwestern Polytechnical University, for also
  reporting this issue. In addition, thanks to Haruki Oyama (Waseda
  University), for also reporting this issue.
2026-07-22 10:19:50 +02:00
W.C.A. Wijngaards aac261cbb3 - Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report. In addition, thanks to Xuanchao Xie,
  for also reporting this issue.
2026-07-22 10:19:02 +02:00
W.C.A. Wijngaards 96f8755520 - Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:18:16 +02:00
W.C.A. Wijngaards 2ce2ca3691 - Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report. In addition, thanks to Xin Wang,
  Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
  for also reporting this issue.
2026-07-22 10:17:32 +02:00
W.C.A. Wijngaards 8c702de175 - Fix CVE-2026-52863, Memory corruption could lead to crash and
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-07-22 10:16:03 +02:00
W.C.A. Wijngaards 804cff4c15 - Fix CVE-2026-50252, Possible cache poisoning attack by mapping
source port population per thread. Thanks to Inbal Schussheim and
  Amit Klein, Hebrew University, for the report.
2026-07-22 10:15:31 +02:00
W.C.A. Wijngaards 3530c81e29 - Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
  for the report.
2026-07-22 10:14:35 +02:00
W.C.A. Wijngaards 1ad8d4c395 - Fix CVE-2026-50046, Possible heap use-after-free in an error path
when a DoT forwarded query is jostled out. Thanks to Qifan Zhang,
  Palo Alto Networks, for the report.
2026-07-22 10:13:36 +02:00
W.C.A. Wijngaards f7637a4f18 - Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via
RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto
  Networks, for the report.
2026-07-22 10:12:38 +02:00
W.C.A. Wijngaards 1e1940383a - Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain'
logic can shadow a stub/forward zone by a legitimate parent's
  NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:12:03 +02:00
W.C.A. Wijngaards 13ec8d0f26 - Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp
the TTL of A/AAAA records disallowing a one-time 'ghost domain'
  delegation renewal via glue records. Thanks to Qifan Zhang, Palo
  Alto Networks, for the report.
2026-07-22 10:11:04 +02:00
W.C.A. Wijngaards 27f22b8808 - Fix CVE-2026-41637, Degradation of resolution service from
improperly accounted client-terminated DNS-over-QUIC queries. Thanks
  to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:10:24 +02:00
W.C.A. Wijngaards 01dfd2f466 - Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
service due to `quic-size` budget bypass. Thanks to N0zoM1z0
  (https://github.com/N0zoM1z0) for the report. In addition, thanks to
  Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
  for also reporting this issue. In addition, thanks to Qifan Zhang,
  Palo Alto Networks, for also reporting this issue. In addition,
  thanks to Xuanchao Xie, for also reporting this issue.
2026-07-22 10:09:26 +02:00
W.C.A. Wijngaards f157c691bb - Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure
in high concurrency DNS-over-QUIC environments. Thanks to Kunta
  Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
  for the report.
2026-07-22 10:08:48 +02:00
W.C.A. Wijngaards 61d6c0e766 - auth-load-thread, implement active thread counter for auth load threads. 2026-07-07 17:21:16 +02:00
W.C.A. Wijngaards b4daa2d0fa - auth-load-thread, use define for constant for number of records before poll. 2026-07-07 16:26:42 +02:00
W.C.A. Wijngaards 425b701fb9 - auth-load-thread, fix memory leak on alloc failure when appending rrset
copy for ixfr main zone data copy.
2026-07-03 16:39:28 +02:00
W.C.A. Wijngaards 0a5cde80f1 - auth-load-thread, auth-task-threads: num config option that enables and
disables the auth load thread.
2026-07-03 14:03:15 +02:00
W.C.A. Wijngaards 55ae8da032 - auth-load-thread, basic test and fixes so it works. 2026-07-02 11:10:06 +02:00
W.C.A. Wijngaards 6bd86df72e - auth-load-thread, simplify cleanup in end transfer load process. 2026-07-02 08:55:13 +02:00
W.C.A. Wijngaards a2f2f53ef9 - auth-load-thread, process end of successful transfer. 2026-07-01 16:54:36 +02:00
W.C.A. Wijngaards b5a03093f6 - auth-load-thread, check for quit during the processing. 2026-07-01 14:41:40 +02:00
W.C.A. Wijngaards 8eba898135 - auth-load-thread, process AXFR, by loading, swap in, delete of old. 2026-07-01 14:27:31 +02:00
W.C.A. Wijngaards 56f66de89f - auth-load-thread, process IXFR, by making a copy, adjust changes, swap in. 2026-07-01 13:05:19 +02:00
W.C.A. Wijngaards 2fbaee2255 - auth-load-thread, process transfer content and swap result back in. 2026-06-30 16:53:27 +02:00
W.C.A. Wijngaards a122490461 - auth-load-thread, poll for quit and process load transfer end. 2026-06-29 16:52:20 +02:00
W.C.A. Wijngaards 380994219f - auth-load-thread, make and run auth load thread. 2026-06-26 17:11:12 +02:00
W.C.A. Wijngaards 1578b6e180 - auth-load-thread, add services/authload.c and services/authload.h 2026-06-26 14:00:04 +02:00
Yorgos Thessalonikefs f6931c794e - Fix memory leak on DNAME 0TTL records. 2026-06-17 17:30:21 +02:00
W.C.A. Wijngaards 45d1e75caf - Fix to check for malloc failure in rpz response create,
for nodata and nxdomain, so it does not crash later.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:59:29 +02:00
W.C.A. Wijngaards e2cc14681e - Fix that malloc failure for rpz_strip_nsdname is
checked and handled, so that it does not crash later.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:53:28 +02:00
W.C.A. Wijngaards 8f2fbd66fc - Fix that malloc failure for ngtcp2_conn_server_new
cleans up reference that older ngtcp2 versions can leave.
  Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-06-17 15:33:06 +02:00
W.C.A. Wijngaards b5909d8d22 - Fix that malloc failure in doq connection setup, does
not crash in doq connection delete later. Thanks to Qifan
  Zhang, Palo Alto Networks, for the report.
2026-06-17 15:29:48 +02:00