mirror of
https://gitlab.isc.org/isc-projects/bind9
synced 2025-09-01 06:55:30 +00:00
Tweak and reword release notes
This commit is contained in:
@@ -16,45 +16,55 @@ Removed Features
|
|||||||
~~~~~~~~~~~~~~~~
|
~~~~~~~~~~~~~~~~
|
||||||
|
|
||||||
- Dynamic updates that add and remove DNSKEY and NSEC3PARAM records no
|
- Dynamic updates that add and remove DNSKEY and NSEC3PARAM records no
|
||||||
longer trigger key rollovers and denial of existence operations. This
|
longer trigger key rollovers and denial-of-existence operations. This
|
||||||
also means that the option :any:`dnssec-secure-to-insecure` has been
|
also means that the :any:`dnssec-secure-to-insecure` option has been
|
||||||
obsoleted. :gl:`#3686`
|
obsoleted. :gl:`#3686`
|
||||||
|
|
||||||
Feature Changes
|
Feature Changes
|
||||||
~~~~~~~~~~~~~~~
|
~~~~~~~~~~~~~~~
|
||||||
|
|
||||||
- The NSEC3PARAM TTL was previously set to 0 and is now changed to be the same
|
- The TTL of the NSEC3PARAM record for every NSEC3-signed zone was
|
||||||
value as in the SOA MINIMUM field. :gl:`#3570`
|
previously set to 0. It is now changed to match the SOA MINIMUM value
|
||||||
|
for the given zone. :gl:`#3570`
|
||||||
|
|
||||||
- A ``configure`` option ``--with-tuning`` has been removed. The compile-time
|
- The ``--with-tuning`` option for ``configure`` has been removed. Each
|
||||||
settings that required different values based on "workload" have been either
|
of the compile-time settings that required different values based on
|
||||||
removed or a sensible default has been picked. :gl:`#3664`
|
the "workload" (which were previously affected by the value of the
|
||||||
|
``--with-tuning`` option) has either been removed or changed to a
|
||||||
|
sensible default. :gl:`#3664`
|
||||||
|
|
||||||
- The option :any:`auto-dnssec` is deprecated and will be removed in 9.19.
|
- The :any:`auto-dnssec` option has been deprecated and will be removed
|
||||||
Please migrate to :any:`dnssec-policy`. :gl:`#3667`
|
in a future BIND 9.19.x release. Please migrate to
|
||||||
|
:any:`dnssec-policy`. :gl:`#3667`
|
||||||
|
|
||||||
- Remove setting the operating system limit (``coresize``, ``datasize``,
|
- The ``coresize``, ``datasize``, ``files``, and ``stacksize`` options
|
||||||
``files`` and ``stacksize``) from ``named.conf``. These options should be set
|
have been removed. The limits these options set should be enforced
|
||||||
from the operating system (``ulimit``) or from the process supervisor
|
externally, either by manual configuration (e.g. using ``ulimit``) or
|
||||||
(e.g. ``systemd``). :gl:`#3676`
|
via the process supervisor (e.g. ``systemd``). :gl:`#3676`
|
||||||
|
|
||||||
- On startup, ``named`` will set the current number of open files to maximum
|
- Setting alternate local addresses for inbound zone transfers has been
|
||||||
allowed by the operating system instead of trying to set it to unlimited
|
deprecated. The relevant options (:any:`alt-transfer-source`,
|
||||||
which worked only very briefly on Linux 2.6.28 (and was causing performance
|
:any:`alt-transfer-source-v6`, and :any:`use-alt-transfer-source`)
|
||||||
problems and thus the change was reverted in the kernel). :gl:`#3676`
|
will be removed in a future BIND 9.19.x release. :gl:`#3694`
|
||||||
|
|
||||||
|
- On startup, :iscman:`named` now sets the limit on the number of open
|
||||||
|
files to the maximum allowed by the operating system, instead of
|
||||||
|
trying to set it to "unlimited". :gl:`#3676`
|
||||||
|
|
||||||
Bug Fixes
|
Bug Fixes
|
||||||
~~~~~~~~~
|
~~~~~~~~~
|
||||||
|
|
||||||
- Increase the number of HTTP headers in the statistics channel from
|
- The number of HTTP headers allowed in requests sent to
|
||||||
10 to 100 to accomodate for some browsers that send more that 10
|
:iscman:`named`'s statistics channel has been increased from 10 to
|
||||||
headers by default. :gl:`#3670`
|
100, to accommodate some browsers that send more than 10 headers
|
||||||
|
by default. :gl:`#3670`
|
||||||
|
|
||||||
- Copy TLS identifier when setting up primaries for catalog member
|
- TLS configuration for primary servers was not applied for zones that
|
||||||
zones. :gl:`#3638`
|
were members of a catalog zone. This has been fixed. :gl:`#3638`
|
||||||
|
|
||||||
- Fix an assertion failure in the statschannel caused by reading from the HTTP
|
- :iscman:`named` could crash due to an assertion failure when an HTTP
|
||||||
connection closed prematurely (connection error, shutdown). :gl:`#3693`
|
connection to the statistics channel was closed prematurely (due to a
|
||||||
|
connection error, shutdown, etc.). This has been fixed. :gl:`#3693`
|
||||||
|
|
||||||
- The ``zone <name>/<class>: final reference detached`` log message was
|
- The ``zone <name>/<class>: final reference detached`` log message was
|
||||||
moved from the INFO log level to the DEBUG(1) log level to prevent the
|
moved from the INFO log level to the DEBUG(1) log level to prevent the
|
||||||
@@ -63,20 +73,21 @@ Bug Fixes
|
|||||||
|
|
||||||
- The new name compression code in BIND 9.19.7 was not compressing
|
- The new name compression code in BIND 9.19.7 was not compressing
|
||||||
names in zone transfers that should have been compressed, so zone
|
names in zone transfers that should have been compressed, so zone
|
||||||
transfers were larger than before. :gl:`#3706`
|
transfers were larger than before. This has been fixed. :gl:`#3706`
|
||||||
|
|
||||||
- When a catalog zone is removed from the configuration, in some
|
- When a catalog zone was removed from the configuration, in some cases
|
||||||
cases a dangling pointer could cause a :iscman:`named` process
|
a dangling pointer could cause the :iscman:`named` process to crash.
|
||||||
crash. This has been fixed. :gl:`#3683`
|
This has been fixed. :gl:`#3683`
|
||||||
|
|
||||||
- The ``named`` would wait for some outstanding recursing queries
|
- In certain cases, :iscman:`named` waited for the resolution of
|
||||||
to finish before shutting down. This has been fixed. :gl:`#3183`
|
outstanding recursive queries to finish before shutting down. This was
|
||||||
|
unintended and has been fixed. :gl:`#3183`
|
||||||
- When a zone is deleted from a server, an key management objects related to
|
|
||||||
that zone would be kept in the memory and released only at the server
|
|
||||||
shutdown. This could lead to constantly increasing memory usage for servers
|
|
||||||
with a high zone churn. :gl:`#3727`
|
|
||||||
|
|
||||||
|
- When a zone was deleted from a server, a key management object related
|
||||||
|
to that zone was inadvertently kept in memory and only released upon
|
||||||
|
shutdown. This could lead to constantly increasing memory use on
|
||||||
|
servers with a high rate of changes affecting the set of zones being
|
||||||
|
served. This has been fixed. :gl:`#3727`
|
||||||
|
|
||||||
Known Issues
|
Known Issues
|
||||||
~~~~~~~~~~~~
|
~~~~~~~~~~~~
|
||||||
|
Reference in New Issue
Block a user