Dear Knot Resolver users,
Knot Resolver 6.5.0 has been released!
Bugfixes:
- views: fix "unused tags" error when repeating a tag in views (!1883)
- watchdog: detect file-changes done via rename*() syscall (!1895)
This is relevant for RPZ files and TLS certs+keys.
- DoH fixes for sharing connections among different users (!1844)
- TCP-based connections used Nagle's algorithm since 6.2.0 (!1903)
This mistake significantly increased latencies of such transports.
- local-data: process upper-case names correctly (!1915)
Packaging:
- deb: migrate to sysusers and update packaging (!1857)
- rpm: fix source build against libknot >= 3.6 (!1907)
- python: 3.9+ (!1886), migrated to setuptools (!1889), removed
typing-extensions (!1910)
- Debian 11 is no longer supported
- Debian,Ubuntu: i386 and armhf architectures no longer supported
Improvements:
- decrease RAM usage by a lot (!1901)
- local-data: increase capacity to 63 GiB (logged MDB_MAP_FULL, !1885)
- systemd: use unit's {Runtime,State,Cache}Directory directives instead
of tmpfiles.d (!1853)
- controller: reimplement the notify socket in Python (!1875)
- python: improve Knot Resolver startup procedure (!1893)
Some startup actions previously handled by the manager have been
moved to a separate startup program.
- python: refactoring: utils (!1894), client (!1908)
- allow running under an unknown user, e.g. in containers (!1914)
Incompatible changes:
- remove legacy systemd unit files (kresd@.service,
kres-cache-gc.service) (!1853)
- remove $KRES_LOGGING_TARGET environment variable (!1893)
You can override the default by passing `--logtarget` to
`knot-resolver` command. (!1912)
- docker: remove cross-platform build for linux/arm/v7 (!1904)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v6.5.0/NEWS
Sources:
https://knot-resolver.nic.cz/release/knot-resolver-6.5.0.tar.xz
GPG signature:
https://knot-resolver.nic.cz/release/knot-resolver-6.5.0.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v6.5.0/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE
Dear Knot Resolver users,
Knot Resolver 6.4.1 has been released!
Security:
- DNS-over-QUIC (DoQ) had severe issues, allowing even RCE
Many people reported (some of) these issues to us.
- DNSSEC correctness issues, acting mainly through the aggressive cache:
* dealing with Labels field in RRSIGs being smaller than the signer's
* dealing with NSEC's next-name pointing outside of the zone
Special thanks to Qifan Zhang from Palo Alto Networks.
Improvements:
- docker: upgrade to Debian 13 (!1856)
- update IANA's certificate for root trust anchor bootstrapping (!1845)
Bugfixes:
- /local-data/addresses*: make multiple addresses work (#808, #954)
- views: fix protocol-based matching for DoQ
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v6.4.1/NEWS
Sources:
https://knot-resolver.nic.cz/release/knot-resolver-6.4.1.tar.xz
GPG signature:
https://knot-resolver.nic.cz/release/knot-resolver-6.4.1.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v6.4.1/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE
Dear Knot Resolver users,
Knot Resolver 5.7.7 has been released!
Security:
- DNSSEC correctness issues, acting mainly through the aggressive cache:
* dealing with Labels field in RRSIGs being smaller than the signer's
* dealing with NSEC's next-name pointing outside of the zone
Special thanks to Qifan Zhang from Palo Alto Networks.
Improvements:
- support cmocka 2.0.0
- avoid AD=1 in reply if ANSWER+AUTHORITY are empty (#914)
- packaging: rpm: require python3-setuptools (!1831)
- packaging: rpm: provide user/group (!1838)
This should also resolve the issue with user and group
configuration during installation (GH#130).
- make DoH cache-control header respect our cache's TTL limits (!1832)
- support libdnssec merged into libknot, as planned for knot >= 3.6 (!1833)
- update IANA's certificate for root trust anchor bootstrapping (!1862)
Bugfixes:
- respect disablement of QNAME case randomization even after TCP issues
- cache: fix wrong TTL in some cases, typically 32768
- reduce excessive caching of some uncommon failed answers (!1832)
- dns64: fix CNAME problems again (#797, !1862)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v5.7.7/NEWS
Sources:
https://knot-resolver.nic.cz/release/knot-resolver-5.7.7.tar.xz
GPG signature:
https://knot-resolver.nic.cz/release/knot-resolver-5.7.7.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v5.7.7/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE
Dear Knot Resolver users,
Knot Resolver 6.1.0, the first officially stable version 6, has been
released!
As of this release, version 6 is preferred over version 5.
Improvements:
- logging: improved logging groups (!1768)
- support libdnssec merged into libknot, as planned for knot >= 3.6 (!1769)
- support cmocka 2.0.0 (!1772)
- avoid AD=1 in reply if ANSWER+AUTHORITY are empty (#914, !1780)
- defer: enabled by default in declarative configuration (!1785)
- /defer/enable: false -> true
- datamodel: lua: added Lua scripts for policy-loader (!1771)
Bugfixes:
- reload did not apply changes to /fallback (!1763)
- fix config.cache.clear test on apple silicon (!1766)
- cache: fix wrong TTL in some cases, typically 32768 (!1774)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v6.1.0/NEWS
Sources:
https://secure.nic.cz/files/knot-resolver/knot-resolver-6.1.0.tar.xz
GPG signature:
https://secure.nic.cz/files/knot-resolver/knot-resolver-6.1.0.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v6.1.0/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE