aboutsummaryrefslogtreecommitdiff
path: root/net/unbound
Commit message (Collapse)AuthorAge
* unbound: update to 1.19.3Jan Klos2024-03-18
| | | | Signed-off-by: Jan Klos <jan@klos.xyz>
* unbound: spell fixPaul Donald2024-03-17
| | | | | | Closes openwrt/luci#6993 Signed-off-by: Paul Donald <newtwen@gmail.com>
* unbound: bump releaseJan Klos2024-03-17
| | | | Signed-off-by: Jan Klos <jan@klos.xyz>
* unbound: add file parameter to service instanceJan Klos2024-03-17
| | | | | | | | that way, procd does not needlessly restart unbound on triggers when everything remains the same - changes in non-default included configuration files will not be registered, however Signed-off-by: Jan Klos <jan@klos.xyz>
* unbound: remove date/time from config headersJan Klos2024-03-17
| | | | | | | so that procd can decide whether to restart unbound based on config file changes Signed-off-by: Jan Klos <jan@klos.xyz>
* unbound: update to latest upstream release version 1.19.1S. Brusch2024-02-18
| | | | | | | | Maintainer: @EricLuehrsen Fixes: CVE-2023-50387, CVE-2023-50868 Release notes: https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/ Run tested: BPi-R3, mediatek/filogic, OpenWrt 23.05.2 Signed-off-by: S. Brusch <ne20002@gmx.ch>
* unbound: fix `create_host_record_from_host` error when `dns` is not setJulien Cassette2023-11-22
| | | | | | | | | | The function `create_host_record_from_host` fails if the `dns` option is not set in the host entry. This sets a default to the `dns` variable in order to fix this error. Fixes: #22691 Signed-off-by: Julien Cassette <julien.cassette@gmail.com>
* unbound: update to 1.19.0Eric Luehrsen2023-11-13
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: create extra host records from DHCP static leasesJulien Cassette2023-11-13
| | | | | | | | | | | The "Extra DNS" option allows to create records from the DHCP "Hostnames" configuration entries. This allows to create such records from the DHCP "Static leases" configuration entries too. Fixes: #22593 Signed-off-by: Julien Cassette <julien.cassette@gmail.com>
* unbound: update to 1.18.0Eric Luehrsen2023-09-09
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* Unbound: Silence SSL unexpected eof messagesTed Hess2023-08-21
| | | | | | | | | | Refs: https://github.com/NLnetLabs/unbound/issues/812 https://github.com/NLnetLabs/unbound/issues/846 This is a backport of: https://github.com/NLnetLabs/unbound/commit/d7e7761 and can be removed with the next release/update of the Unbound package Signed-off-by: Ted Hess <thess@kitschensync.net>
* unbound: update to version 1.17.1Josef Schlehofer2023-02-10
| | | | | | | - Refreshed one patch - Removed deprecated AUTORELEASE Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
* unbound: fix local_subnet for IPv6 addresses that contain a portMark Mentovai2022-12-20
| | | | | | | | | | | This prevents a forwarding server named like ::1@5453 from being added to unbound.conf as a forward-host instead of the correct forward-addr. forward-host requires the name to be resolved, which is impossible in the absence of another nameserver. Thus, forwarding-only configurations referencing only the IPv6 loopback address with a port number were broken. Signed-off-by: Mark Mentovai <mark@mentovai.com>
* unbound: update to 1.17.0Eric Luehrsen2022-11-21
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: update control cert uci processingRob Ekl2022-10-09
| | | | Signed-off-by: Rob Ekl <ekl.rob@gmail.com>
* unbound: update to version 1.16.3Josef Schlehofer2022-09-25
| | | | | | | | | Changelog: https://www.nlnetlabs.nl/projects/unbound/download/#unbound-1-16-3 - Fixes: CVE-2022-3204 Refreshed one patch Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
* unbound: update to 1.16.2, fix CVE-2022-30698, CVE-2022-30699Pascal Ernster2022-08-02
| | | | | | | | | Maintainer: @EricLuehrsen Compile tested: x86/64 Run tested: x86/64 Description: Update to 1.16.2, fix CVE-2022-30698 and CVE-2022-30699. Signed-off-by: Pascal Ernster <git@hardfalcon.net>
* unbound: update to 1.16.1Pascal Ernster2022-07-19
| | | | | | | | | Maintainer: @EricLuehrsen Compile tested: realtek/rtl838x, x86/64 Run tested: realtek/rtl838x, x86/64 Description: Update to 1.16.1 Signed-off-by: Pascal Ernster <git@hardfalcon.net>
* unbound: update to 1.16.0Stijn Segers2022-06-19
| | | | Signed-off-by: Stijn Segers <foss@volatilesystems.org>
* unbound: update to version 1.15.0Josef Schlehofer2022-02-11
| | | | | | Refresh patch Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
* unbound: update to 1.14.0Eric Luehrsen2021-12-10
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: backport fix for permission denied errorAnsuel Smith2021-09-08
| | | | | | | | Currently there is a problem with log spam when ipv6 network is dropped. Fix this by backporting a patch to silence these errors when verbose logging is not enabled. Signed-off-by: Ansuel Smith <ansuelsmth@gmail.com>
* unbound: update to 1.3.2Eric Luehrsen2021-08-17
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: fix build on non-linux systemsFelix Fietkau2021-06-16
| | | | | | Override places that call uname to detect target features Signed-off-by: Felix Fietkau <nbd@nbd.name>
* Merge pull request #15474 from ja-pa/unbound-ttl-negRosen Penev2021-05-07
|\ | | | | unbound: add cache-max-negative-ttl config option
| * unbound: add cache-max-negative-ttl config optionJan Pavlinec2021-04-20
| | | | | | | | Signed-off-by: Jan Pavlinec <jan.pavlinec@nic.cz>
* | unbound: fix typo in assist name of https-dns-proxyPeter van Dijk2021-04-25
|/ | | | | | I left the old version in, in case users have configs that already correct for this error. Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
* unbound: update to 1.13.1Eric Luehrsen2021-02-22
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* treewide: Run refresh on all packagesIlya Lipnitskiy2021-02-20
| | | | | | | | | The crude loop I wrote to come up with this changeset: find -L package/feeds/packages/ -name patches | \ sed 's/patches$/refresh/' | sort | xargs make Signed-off-by: Ilya Lipnitskiy <ilya.lipnitskiy@gmail.com>
* unbound: update to 1.13.0Eric Luehrsen2020-12-04
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: clean up interface interpretation in UCIEric Luehrsen2020-11-04
| | | | | | | | | DNS flag day 2020, software should reflect the minimum EDNS 1232 bytes. Added iface_wan and iface_lan to control internal DNS assignemnts and to control what is local service ACL. Interface wild cards are not explicitly set so that they can be customized in extended conf. Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: update to 1.1.12Eric Luehrsen2020-11-04
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: improve odhcpd rapid update robustnessEric Luehrsen2020-09-05
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: add option for dnstap supportJan Pavlinec2020-09-03
| | | | Signed-off-by: Jan Pavlinec <jan.pavlinec@nic.cz>
* unbound: follow resolv.conf.auto to new locationEric Luehrsen2020-08-07
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: update to 1.11.0Eric Luehrsen2020-07-29
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: improve startup and dhcp script robustnessEric Luehrsen2020-07-12
| | | | | | | | | - prevent rapid overlap in DHCP script updates - check and allow localhost forwards with specific applications - add option for rate limiting inbound queries - change UCI list to table format with Unbound conf references Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: add dns assistants on local hostEric Luehrsen2020-06-27
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: refactor build options to select switchesEric Luehrsen2020-06-27
| | | | | | | | | | The two unique packages "Unbound light" and "Unbound heavy" were not working well due to the fact that Unbound is mostly its library. Tools and helpers would crash. Instead a reasonable default Unbound is built. Also up select options like python are added. libevent and libpthreads are options to down select. Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: make option interface_auto default onEric Luehrsen2020-06-13
| | | | | | | | | | Unbound has a quirk and may reply on a different device address. When Unbound answers with from-address different than it received queries on, it may cause trouble for select VPN and firewall configurations. Ensure Unbound replies with the same address by changing this default. Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* Merge pull request #12400 from EricLuehrsen/masterRosen Penev2020-06-04
|\ | | | | unbound: suggest matched domain option for dnsmasq link
| * unbound: suggest matched domain option for dnsmasq linkEric Luehrsen2020-06-04
| | | | | | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* | unbound: bump PKG_RELEASEDavid Bauer2020-06-04
|/ | | | | | Fixes commit da76aeb24c1b ("unbound: expose interface-auto to UCI") Signed-off-by: David Bauer <mail@david-bauer.net>
* unbound: expose interface-auto to UCIDavid Bauer2020-06-03
| | | | | | | | | | | | | | | This exposes the interface-auto option to UCI. By default, interface-auto is disabled. This leads to the DNS reply possibly originating from a different address then the request was sent to. Devices with a packet filter might not receive the reply in this case. Enabling interface-auto ensures the reply is sent with the source-address the request was sent to. Signed-off-by: David Bauer <mail@david-bauer.net>
* unbound: update to version 1.10.1Josef Schlehofer2020-05-19
| | | | | | | | Fixes: CVE-2020-12662 CVE-2020-12663 Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
* unbound: enable ipset support for the unbound-daemon-heavy variant.Stijn Segers2020-02-23
| | | | | | | | | | | This patch enables ipset support in the unbound-daemon-heavy variant. See [1] for instructions on how to use it. Also fix a minor typo in the libunbound-light description. [1] https://github.com/NLnetLabs/unbound/pull/28 Signed-off-by: Stijn Segers <foss@volatilesystems.org>
* Unbound: update to 1.10.0Stijn Segers2020-02-23
| | | | Signed-off-by: Stijn Segers <foss@volatilesystems.org>
* unbound: improve dependencies for okpgEric Luehrsen2020-01-17
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: fix TLS forwards with optional suffixEric Luehrsen2020-01-11
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* unbound: update to 1.9.6Eric Luehrsen2019-12-18
| | | | Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>