2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-22 01:59:26 +00:00

Tweak and reword release notes

This commit is contained in:
Andoni Duarte Pintado 2025-08-12 10:40:46 +02:00
parent f2ba8924a4
commit 4829cdab26

View File

@ -15,44 +15,42 @@ Notes for BIND 9.21.11
New Features New Features
~~~~~~~~~~~~ ~~~~~~~~~~~~
- Support for parsing the DSYNC record has been added. - Support for parsing DSYNC records has been added.
:gl:`#5440` These records are used for discovering the receiver endpoint for DNS
notification messages. For more information, see
`draft-ietf-dnsop-generalized-notify-09`_. :gl:`#5440`
.. _`draft-ietf-dnsop-generalized-notify-09`: https://datatracker.ietf.org/doc/draft-ietf-dnsop-generalized-notify/09/
Feature Changes Feature Changes
~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~
- Reword the 'shut down hung fetch while resolving' message. - Reword the ``shut down hung fetch while resolving`` message.
The log message 'shut down hung fetch while resolving' may be The log message ``shut down hung fetch while resolving`` may be
confusing because no detection of hung fetches actually takes place, confusing, because no detection of hung fetches actually takes place.
but rather the timer on the fetch context expires and the resolver Instead, the timer on the fetch context expires and the resolver
gives up. gives up.
Change the log message to actually say that instead of the original The log message has been changed to actually indicate that, instead of the
cryptic message about hung fetch. :gl:`#3148` original cryptic message about hung fetch. :gl:`#3148`
- Use native shared library extension.
Use the native shared library extension when build loadable libaries.
For most platforms this is ".so" but for Darwin it is ".dylib".
:gl:`#5375`
- Plugin extension in plugin path is now optional. - Plugin extension in plugin path is now optional.
Plugin configuration no longer requires the library file extension, so Plugin configuration no longer requires the library file extension, so
it is now possible to invoke a plugin using the syntax `plugin query it is now possible to invoke a plugin using the syntax ``plugin query
"library"` instead of `plugin query "libary.so"`. :gl:`#5377` "library"`` instead of ``plugin query "library.so"``. :gl:`#5377`
- Add deprecation warnings for RSASHA1, RSASHA1-NSEC3SHA1 and DS digest - Add deprecation warnings for RSASHA1, RSASHA1-NSEC3SHA1, and DS digest
type 1. type 1.
RSASHA1 and RSASHA1-NSEC-SHA1 DNSKEY algorithms have been deprecated RSASHA1 and RSASHA1-NSEC-SHA1 DNSKEY algorithms have been deprecated
by the IETF and should no longer be used for DNSSEC. DS digest type 1 by the IETF and should no longer be used for DNSSEC. DS digest type 1
(SHA1) has also been deprecated. Validators are now expected to treat (SHA1) has also been deprecated in BIND 9. Validators are now expected to treat
these algorithms and digest as unknown, resulting in some zones being these algorithms and digest as unknown, resulting in some zones being
treated as insecure when they were previously treated as secure. treated as insecure when they were previously treated as secure.
Warnings have been added to named and tools when these algorithms and Warnings have been added to :iscman:`named` and tools when these algorithms and
this digest are being used for signing. this digest are being used for signing.
Zones signed with RSASHA1 or RSASHA1-NSEC-SHA1 should be migrated to a Zones signed with RSASHA1 or RSASHA1-NSEC-SHA1 should be migrated to a
@ -60,34 +58,32 @@ Feature Changes
Zones with DS or CDS records with digest type 1 (SHA1) should be Zones with DS or CDS records with digest type 1 (SHA1) should be
updated to use a different digest type (e.g. SHA256) and the digest updated to use a different digest type (e.g. SHA256) and the digest
type 1 records should be removed. type 1 records should be removed. :gl:`#5358`
Related to #5358
Bug Fixes Bug Fixes
~~~~~~~~~ ~~~~~~~~~
- Stale RRsets in a CNAME chain were not always refreshed. - Stale RRsets in a CNAME chain were not always refreshed.
With serve-stale enabled, a CNAME chain that contains a stale RRset, Previously, with serve-stale enabled and a CNAME chain that contained a stale RRset,
the refresh query doesn't always properly refresh the stale RRsets. the refresh query didn't always properly refresh the stale RRsets.
This has been fixed. :gl:`#5243` This has been fixed. :gl:`#5243`
- Add RPZ extended DNS error for zones with a CNAME override policy - Add RPZ extended DNS error for zones with a CNAME override policy
configured. configured.
When the zone is configured with a CNAME override policy, or the Previously, when the zone was configured with a CNAME override policy, or the
response policy zone contains a wildcard CNAME, the extended DNS error response policy zone contained a wildcard CNAME, the extended DNS error
code was not added. This has been fixed. :gl:`#5342` code was not added. This has been fixed. :gl:`#5342`
- Fix cross builds. - Fix cross builds.
Cross-compilation did not work even when the ``-Ddoc=disabled`` build Cross-compilation did not work even when the ``-Ddoc=disabled`` build
option was passed to Meson due to the build targets used for option was passed to Meson, because the build targets used for
generating documentation depending on a non-native executable. This generating documentation depended on a non-native executable. This
has been fixed. :gl:`#5379` has been fixed. :gl:`#5379`
- Fix named-makejournal man page installation. - Fix :iscman:`named-makejournal` man page installation.
The man page for :iscman:`named-makejournal` was erroneously not The man page for :iscman:`named-makejournal` was erroneously not
installed when building from a source tarball. This has been fixed. installed when building from a source tarball. This has been fixed.
@ -96,43 +92,42 @@ Bug Fixes
- Fix plugin loading. - Fix plugin loading.
Loading plugins specified using just the shared library name (i.e. Loading plugins specified using just the shared library name (i.e.
without using an absolute path or a relative path) did not work. This without using an absolute or relative path) did not work. This
has been fixed. :gl:`#5379` has been fixed. :gl:`#5379`
- Fix dig issues. - Fix :iscman:`dig` issues.
When used with the ``+keepopen`` option with a TCP connection, When used with the ``+keepopen`` option,
iscman:`dig` could terminate unexpectedly in rare situations. :iscman:`dig` could terminate unexpectedly in rare situations.
Additionally, iscman:`dig` could hang and fail to shutdown properly Additionally, :iscman:`dig` could hang and fail to shutdown properly
when interrupted during a query. These have been fixed. :gl:`#5381` when interrupted during a query. These have been fixed. :gl:`#5381`
- Log dropped or slipped responses in the query-errors category. - Log dropped or slipped responses in the ``query-errors`` category.
Responses which were dropped or slipped because of RRL (Response Rate Responses which were dropped or slipped because of Response Rate
Limiting) were logged in the ``rate-limit`` category instead of the Limiting (RRL) were logged in the ``rate-limit`` category instead of the
``query-errors`` category, as documented in ARM. This has been fixed. ``query-errors`` category, as documented in the ARM. This has been fixed.
:gl:`#5388` :gl:`#5388`
- Synth-from-dnssec was not working in some scenarios. - :any:`synth-from-dnssec` was not working in some scenarios.
Aggressive use of DNSSEC-Validated cache with NSEC was not working in Aggressive use of DNSSEC-Validated cache with NSEC was not working in
scenarios when no parent NSEC was not in cache. This has been fixed. scenarios when no parent NSEC was in cache. This has been fixed.
:gl:`#5422` :gl:`#5422`
- Clean enough memory when adding new ADB names/entries under memory - Clean enough memory when adding new ADB names/entries under memory
pressure. pressure.
The ADB memory cleaning is opportunistic even when we are under memory The ADB memory cleaning is opportunistic even when BIND is under memory
pressure (in the overmem condition). Split the opportunistic LRU pressure (in the overmem condition). :iscman:`named` now ensures that the assigned memory
cleaning and overmem cleaning and make the overmem cleaning always limit is not exceeded by releasing twice the amount of memory
cleanup double of the newly allocated adbname/adbentry to ensure we allocated for each new ADB name/entry when under memory pressure.
never allocate more memory than the assigned limit. :gl:`!10637`
- Prevent spurious validation failures. - Prevent spurious validation failures.
Under rare circumstances, validation could fail if multiple clients Under rare circumstances, validation could fail if multiple clients
simultaneously iterated the same set of signatures. simultaneously iterated the same set of DNSSEC signatures. This has
been fixed. :gl:`#3014`
References #3014