2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-09-01 06:55:30 +00:00

Tweak and reword release notes

This commit is contained in:
Michał Kępień
2022-12-12 12:11:01 +01:00
parent 64985af9fc
commit d4801a9163

View File

@@ -16,45 +16,55 @@ Removed Features
~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~
- Dynamic updates that add and remove DNSKEY and NSEC3PARAM records no - Dynamic updates that add and remove DNSKEY and NSEC3PARAM records no
longer trigger key rollovers and denial of existence operations. This longer trigger key rollovers and denial-of-existence operations. This
also means that the option :any:`dnssec-secure-to-insecure` has been also means that the :any:`dnssec-secure-to-insecure` option has been
obsoleted. :gl:`#3686` obsoleted. :gl:`#3686`
Feature Changes Feature Changes
~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~
- The NSEC3PARAM TTL was previously set to 0 and is now changed to be the same - The TTL of the NSEC3PARAM record for every NSEC3-signed zone was
value as in the SOA MINIMUM field. :gl:`#3570` previously set to 0. It is now changed to match the SOA MINIMUM value
for the given zone. :gl:`#3570`
- A ``configure`` option ``--with-tuning`` has been removed. The compile-time - The ``--with-tuning`` option for ``configure`` has been removed. Each
settings that required different values based on "workload" have been either of the compile-time settings that required different values based on
removed or a sensible default has been picked. :gl:`#3664` the "workload" (which were previously affected by the value of the
``--with-tuning`` option) has either been removed or changed to a
sensible default. :gl:`#3664`
- The option :any:`auto-dnssec` is deprecated and will be removed in 9.19. - The :any:`auto-dnssec` option has been deprecated and will be removed
Please migrate to :any:`dnssec-policy`. :gl:`#3667` in a future BIND 9.19.x release. Please migrate to
:any:`dnssec-policy`. :gl:`#3667`
- Remove setting the operating system limit (``coresize``, ``datasize``, - The ``coresize``, ``datasize``, ``files``, and ``stacksize`` options
``files`` and ``stacksize``) from ``named.conf``. These options should be set have been removed. The limits these options set should be enforced
from the operating system (``ulimit``) or from the process supervisor externally, either by manual configuration (e.g. using ``ulimit``) or
(e.g. ``systemd``). :gl:`#3676` via the process supervisor (e.g. ``systemd``). :gl:`#3676`
- On startup, ``named`` will set the current number of open files to maximum - Setting alternate local addresses for inbound zone transfers has been
allowed by the operating system instead of trying to set it to unlimited deprecated. The relevant options (:any:`alt-transfer-source`,
which worked only very briefly on Linux 2.6.28 (and was causing performance :any:`alt-transfer-source-v6`, and :any:`use-alt-transfer-source`)
problems and thus the change was reverted in the kernel). :gl:`#3676` will be removed in a future BIND 9.19.x release. :gl:`#3694`
- On startup, :iscman:`named` now sets the limit on the number of open
files to the maximum allowed by the operating system, instead of
trying to set it to "unlimited". :gl:`#3676`
Bug Fixes Bug Fixes
~~~~~~~~~ ~~~~~~~~~
- Increase the number of HTTP headers in the statistics channel from - The number of HTTP headers allowed in requests sent to
10 to 100 to accomodate for some browsers that send more that 10 :iscman:`named`'s statistics channel has been increased from 10 to
headers by default. :gl:`#3670` 100, to accommodate some browsers that send more than 10 headers
by default. :gl:`#3670`
- Copy TLS identifier when setting up primaries for catalog member - TLS configuration for primary servers was not applied for zones that
zones. :gl:`#3638` were members of a catalog zone. This has been fixed. :gl:`#3638`
- Fix an assertion failure in the statschannel caused by reading from the HTTP - :iscman:`named` could crash due to an assertion failure when an HTTP
connection closed prematurely (connection error, shutdown). :gl:`#3693` connection to the statistics channel was closed prematurely (due to a
connection error, shutdown, etc.). This has been fixed. :gl:`#3693`
- The ``zone <name>/<class>: final reference detached`` log message was - The ``zone <name>/<class>: final reference detached`` log message was
moved from the INFO log level to the DEBUG(1) log level to prevent the moved from the INFO log level to the DEBUG(1) log level to prevent the
@@ -63,20 +73,21 @@ Bug Fixes
- The new name compression code in BIND 9.19.7 was not compressing - The new name compression code in BIND 9.19.7 was not compressing
names in zone transfers that should have been compressed, so zone names in zone transfers that should have been compressed, so zone
transfers were larger than before. :gl:`#3706` transfers were larger than before. This has been fixed. :gl:`#3706`
- When a catalog zone is removed from the configuration, in some - When a catalog zone was removed from the configuration, in some cases
cases a dangling pointer could cause a :iscman:`named` process a dangling pointer could cause the :iscman:`named` process to crash.
crash. This has been fixed. :gl:`#3683` This has been fixed. :gl:`#3683`
- The ``named`` would wait for some outstanding recursing queries - In certain cases, :iscman:`named` waited for the resolution of
to finish before shutting down. This has been fixed. :gl:`#3183` outstanding recursive queries to finish before shutting down. This was
unintended and has been fixed. :gl:`#3183`
- When a zone is deleted from a server, an key management objects related to
that zone would be kept in the memory and released only at the server
shutdown. This could lead to constantly increasing memory usage for servers
with a high zone churn. :gl:`#3727`
- When a zone was deleted from a server, a key management object related
to that zone was inadvertently kept in memory and only released upon
shutdown. This could lead to constantly increasing memory use on
servers with a high rate of changes affecting the set of zones being
served. This has been fixed. :gl:`#3727`
Known Issues Known Issues
~~~~~~~~~~~~ ~~~~~~~~~~~~