head	1.1;
branch	1.1.1;
access;
symbols
	netbsd-11:1.1.1.1.0.2
	unbound-1-26-1:1.1.1.1
	NLNETLABS:1.1.1;
locks; strict;
comment	@# @;


1.1
date	2026.09.17.14.22.54;	author christos;	state Exp;
branches
	1.1.1.1;
next	;
commitid	fayiV3BcuZyYSYVG;

1.1.1.1
date	2026.09.17.14.22.54;	author christos;	state Exp;
branches
	1.1.1.1.2.1;
next	;
commitid	fayiV3BcuZyYSYVG;

1.1.1.1.2.1
date	2026.09.17.14.22.54;	author martin;	state dead;
branches;
next	1.1.1.1.2.2;
commitid	Ryg7Jl4383JDMHYG;

1.1.1.1.2.2
date	2026.10.08.18.50.57;	author martin;	state Exp;
branches;
next	;
commitid	Ryg7Jl4383JDMHYG;


desc
@@


1.1
log
@Initial revision
@
text
@ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN SOA
SECTION ANSWER
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN AXFR
SECTION ANSWER
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
example.com.	IN NS	ns.example.net.
www.example.com. IN A	1.2.3.4
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN SOA
SECTION ANSWER
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
example2.com.	IN NS	ns.example2.net.
EXTRA_PACKET
REPLY QR AA NOERROR
; too slow
ADJUST packet_sleep=5
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
extra.example2.com. IN A 1.2.3.5
EXTRA_PACKET
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
www.example2.com. IN A	1.2.3.4
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id sleep=5
REPLY QR AA NOERROR
SECTION QUESTION
prim.example.net. IN A
SECTION ANSWER
prim.example.net. IN A 127.0.0.1
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id sleep=5
REPLY QR AA NOERROR
SECTION QUESTION
notif.example.net. IN A
SECTION ANSWER
notif.example.net. IN A 127.0.0.1
ENTRY_END
@


1.1.1.1
log
@Import unbound-1.26.1 (previous was unbound-1.25.1)

Unbound 1.26.1
==============
This release has a number of security fixes.
The release is signed with the OpenPGP software signing key that is
in use since Jan 1st 2026:
User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl
Key ID: A144 323D EAAC DF45
Fingerprint: 2310 1869 0C4D 903E F419  146A A144 323D EAAC DF45

The key is available from https://nlnetlabs.nl/signing-keys .
This release consolidates security fixes for issues reported over
a period of time. There are fixes for CVE-2026-77860, CVE-2026-77955,
CVE-2026-78227, CVE-2026-80225, CVE-2026-81634, CVE-2026-81642,
CVE-2026-82717, CVE-2026-82720 and CVE-2026-85501.

Bug Fixes
Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code
Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li
from Nankai University, AOSP Lab for the report.
Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC
canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber,
for the report.
Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption.
Thanks to Ben Morris from Anthropic for the report.
Fix CVE-2026-77955, Possible ZONEMD verification bypass window.
Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab,
for the report. In addition, thanks to Qifan Zhang from Palo Alto
Networks for also reporting this issue.
Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on
reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai
University, AOSP Lab for the report.
Fix CVE-2026-80225, Possible degradation of service from continuous
queries on the same TCP/DoT connection. Thanks to Qifan Zhang from
Palo Alto Networks for the report.
Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path.
Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab,
for the report.
Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch
Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and
Xiang Li from Nankai University, AOSP Lab for the report. In
addition, thanks to Qifan Zhang from Palo Alto Networks for a
complimentary report.
Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'.
Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the
University of Science and Technology of China (USTC) for the
report.

Unbound 1.26.0
==============
This release has some features and a number of bug fixes.
The release is signed with the OpenPGP software signing key that is
in use since Jan 1st 2026:
User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl
Key ID: A144 323D EAAC DF45
Fingerprint: 2310 1869 0C4D 903E F419  146A A144 323D EAAC DF45

The key is available from https://nlnetlabs.nl/signing-keys .
The certificates for the root key are updated. The icannbundle.pem
file is updated with the public keys for 2009 to 2029 and for 2025
to 2045. This is available in the unbound-anchor tool. With the
-l option unbound-anchor lists the builtin key and cert that it
has. The updated certificates are valid for a longer time. With
-c the icannbundle.pem file can be given from the commandline.
Then unbound-anchor does not use the builtin certificates. And
this allows the update of the certificate file without a change
in unbound-anchor.
The ipsecmod module is changed, that the script, for the hook, has
to start with a line like #!/bin/sh. The file is executed with
execv, and not any longer with system, so that it is better for
security. It is an in-depth protection against possible quotation
and buffer failures.
The server continues to start if secondary zones, for auth zones,
fail to load from zonefile. To protects against malformed content
in the zonefiles, and the server continues to serve, and attempt
to fetch new updates for the zone. Also for primary auth zones, if
the zonefile does not exist, the server continues to start up. This
makes the server start more easily. Secondary zones are no longer
allowed to have a $INCLUDE in the zonefile. That is for safety,
for what file is chosen. The server drops out-of-zone content from
auth zones when they are read, those records are not supposed to be
part of the auth zone. The primary hostname that is transferred from,
can now be a name that uses CNAME(s).
The options max-transfer-size and max-transfer-time can be used
to limit the amount of size and time that auth-zone transfers use. The
default is disabled, that is backwards compatible.
The unbound-control command local_data_remove is overloaded to also
work to be able to remove specific records. Specify the record with
its details to remove it.
Apart from the local-zone type block_a, that denies A lookups,
there is now also block_aaaa, it denies AAAA lookups. The local zone
types block_a_wdata and block_aaaa_wdata can be used to also have
local-data, that is served, if it is not there, like transparent, it
lookups recursively, or denies the particular type from lookup. These
are helpful in IPv4 with IPv6 deployment situations, as it forces
applications to not use a particular transport. With the changes to
respip and RPZ processing that make the filters apply equally after
dns64, so that dns64 does not bypass the filter, the new local-zone
types can be used to apply denial of a particular transport.

Features
Update icannbundle.pem certificates in unbound-anchor. It
has the public keys for 2009 to 2029 and for 2025 to 2045.
Fix to add max-transfer-size and max-transfer-time that
limit auth-zone and rpz transfer amount and time taken.
Default is disabled. This hardens against unbounded
transfers. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Merge #1087: Overload local_data_remove to support removing
specific records.
Merge #1433 from jisakiel: Add new static zone type
block_aaaa to suppress AAAA queries.
Fix #1477: respip + dns64: dns64 uses A records modified by
respip instead of original A records. Adds local-zone types
block_a_wdata and block_aaaa_wdata, that are like block_a
and block_aaaa, and uses local-data if present.

Bug Fixes
Fix windows 64bit build for libssp dependency.
iana portlist updated.
Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation
in setup_if() - outside_network_create(). This fixes that
large values for num_ports do not overflow and create
invalid references after integer truncation. Thanks
to Karnakar Reddy (@@karnakarreddi) for the report.
Fix to clean up log ids after a failure to start a worker thread.
Fix to relax assertions after the TTL 0 handling change.
This relaxes an assertion in cachedb (it fails instead),
and for packet_rrset_copy_region.
Fix comment and verbose logging for EDNS fallback buffer size.
Fix man page entry for so-sndbuf, it is for responses sent out.
Fix val_find_DS for robustness, to check the result of
packet_rrset_copy_region before using it. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report.
Fix that for dns64 answers, the AAAA query is checked to be
DNSSEC validated, when DNSSEC is enabled. This improves
the RFC6147 conformance of Unbound. Thanks to Xin Wang
and Jiajia Liu, Northwestern Polytechnical University, for
the report. In addition, thanks to Qifan Zhang, Palo Alto
Networks, for reporting it.
Fix for allocation-failure hardening of rrset cache wildcard
storage and canonical NSEC owner replacement. Thanks to Xin
Wang and Jiajia Liu, Northwestern Polytechnical University,
for the report.
Fix DNSSEC validation with libnettle for noncanonical RSA
DNSKEYs with leading zeroes for n. Thanks to Xin Wang and
Jiajia Liu, Northwestern Polytechnical University, for
the report.
Fix DNSKEY size calculation for noncanonical RSA DNSKEYs
with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu,
Northwestern Polytechnical University, for the report.
Fix for mixed class referrals, the resolver uses the query
class. Thanks to Xin Wang and Jiajia Liu, Northwestern
Polytechnical University, for the report.
Unit test for CVE-2026-33278.
Unit test for CVE-2026-42944.
Unit test for CVE-2026-42959.
Unit test for CVE-2026-40622.
Unit test for CVE-2026-42960.
Fix in depth for serve-expired responses from cachedb, that it
does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix lame server detection, for selfpointed glue records.
Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua
University for the report.
Fix cleaning up DoH session. The same query can be on multiple
streams in a session. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix for signed same-owner CNAME and ordinary RRset responses.
Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical
University, for the report.
Fix for mesh new client and mesh new callback to rollback the
added address, tcp mesh state and callback when there is a failure
to initialize. This fixes the mesh accounting of reply addresses.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
Polytechnical University, for the report
Fix for autotrust state-file line overflow, that can give
hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix to limit the DSNS per-label walk in the iterator. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
Fix that the ratelimit is decremented on successful
referrals. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
Fix that msgencode insert_query has the correct assertion,
for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix to reset the tcp-timeout before applying a load based
reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
Fix to decrement the per-netblock tcp connection limits, so
it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix manual to document ratelimit, that it is for target
nameservers for a domain, and keeps queries limited. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
Fix, in depth, for respip rewrite of dns64 responses. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
Fix that dns64 with subnetcache does not write ECS scoped
answers to global cache. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
Fix ipset module for name too long checks, race conditions
on local name buffer, and for socket close race condition.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix that validator caps number of ANY RRsets it can
validate, and the wait timer is shortened. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
Fix analyzer warning in mesh_new_client.
Fix #1457: race condition causes segfault when starting
threads.
Fix header_seen detection for trust anchor files, so that it
detects the id line.
Fix unit test to check for new icannbundle.pem.
Fix const as reported by newest compiler warnings.
Fix that the processing of class responses does not have
a heap use-after-free. That could happen if at least two
distinct classes are configured for resolution. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia
Liu, Northwestern Polytechnical University, for also
reporting this.
Fix negative cache to work with NSEC3 records without salt.
Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern
Polytechnical University, for the report.
Fix parse of svcbparam ech, it had incorrect length. Thanks
to Qifan Zhang, Palo Alto Networks for the report.
Fix that quotation and escaping works the same in auth-zone
url content, as in the zonefile read. Thanks to Qifan Zhang,
Palo Alto Networks for the report.
Fix ipset module to use larger domain name buffers, and
check buffer lengths. Thanks to Qifan Zhang, Palo Alto
Networks for the report.
Fix PROXYv2 header read and consume, it checks the header
size. Thanks to Qifan Zhang, Palo Alto Networks for
the report.
Fix negative cach...

Unbound 1.25.2
==============
This release has a number of security fixes.
The release is signed with the OpenPGP software signing key that is
in use since Jan 1st 2026:
User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl
Key ID: A144 323D EAAC DF45
Fingerprint: 2310 1869 0C4D 903E F419  146A A144 323D EAAC DF45

The key is available from https://nlnetlabs.nl/signing-keys .
This release consolidates security fixes for issues reported over
a period of time. There are fixes for CVE-2026-14586, CVE-2026-32665,
CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621,
CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045,
CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251,
CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708,
CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991,
CVE-2026-56416 and CVE-2026-56444.

Bug Fixes
Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure
in high concurrency DNS-over-QUIC environments. Thanks to Kunta
Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for the report.
Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
service due to quic-size budget bypass. Thanks to N0zoM1z0
(https://github.com/N0zoM1z0) for the report. In addition, thanks to
Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for also reporting this issue. In addition, thanks to Qifan Zhang,
Palo Alto Networks, for also reporting this issue. In addition,
thanks to Xuanchao Xie, for also reporting this issue.
Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks
to Qifan Zhang, Palo Alto Networks, for the report. In addition,
thanks to Trung Nguyen (@@everping) of CyStack, for also reporting
this issue.
Fix CVE-2026-41637, Degradation of resolution service from
improperly accounted client-terminated DNS-over-QUIC queries. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp
the TTL of A/AAAA records disallowing a one-time 'ghost domain'
delegation renewal via glue records. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
Fix CVE-2026-44621, Libunbound applications configured with
'unwanted-reply-threshold' could eventually be abruptly
terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain'
logic can shadow a stub/forward zone by a legitimate parent's
NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via
RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
Fix CVE-2026-46582, A wildcard replay, as another piece of data,
triggers poisoning in the serve expired reply path. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation
restarts. Thanks to Kunjie Shang, University of Science and
Technology of China, for the report.
Fix CVE-2026-50046, Possible heap use-after-free in an error path
when a DoT forwarded query is jostled out. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers
instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers
defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
Fix CVE-2026-50252, Possible cache poisoning attack by mapping
source port population per thread. Thanks to Inbal Schussheim and
Amit Klein, Hebrew University, for the report.
Fix CVE-2026-52863, Memory corruption could lead to crash and
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix CVE-2026-54478, DNS Cookie bypass when combined with
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
Fix CVE-2026-55708, Privacy/configuration issue when adding local
data in views through 'unbound-control'. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
Alto Networks, for the report. In addition, thanks to Xin Wang,
Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
for also reporting this issue.
Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured
Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
Networks, for the report. In addition, thanks to Xuanchao Xie,
for also reporting this issue.
Fix CVE-2026-56416, Possible heap buffer overflow when validator
canonicalizes RDATA that contains domain name. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-56444, Degradation of resolution service when
'discard-timeout' and 'serve-expired-client-timeout' are combined in
unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
for the report. In addition, thanks to Xin Wang, Jiapeng Li,
and Jiajia Liu, Northwestern Polytechnical University, for also
reporting this issue. In addition, thanks to Haruki Oyama (Waseda
University), for also reporting this issue.
@
text
@@


1.1.1.1.2.1
log
@file fast_reload_authdel.testns was added on branch netbsd-11 on 2026-10-08 18:50:57 +0000
@
text
@d1 78
@


1.1.1.1.2.2
log
@Pull up the following, requested by christos in ticket #510:

	external/bsd/unbound/dist/libunbound/remote.h   up to 1.1.1.1
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/key-setup.sh up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_xfr_host_bogus.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/dns64_dnssec.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/dns64_fwd_nocache.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/dns64_respip_bypass.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/edns_nsid_repeat.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/errreport_agent_domain_len.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fill_reply_uninit.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/ghost_glue_a.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_class_any_merge.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_class_mixreferral.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_dname_ttl0_grace.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_ghost_ns_childapex.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_scrub_mx.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_scrub_ns_min.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_self_glue.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/iter_self_glue_promisc.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/local_block_a.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/nsec_cross_zone.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/respip_bogus_rewrite.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/respip_cname_loop_tagged.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/rpz_clientip_passthru_cache.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/rpz_clientip_passthru_dns64.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/rrsig_agr_wild.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/serve_expired_respip_cname.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/serve_expired_respip_drop.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/serve_expired_rpz_drop.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/serve_expired_rpz_nx.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/serve_expired_wildcard_swap_ad.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/stop_nxdomain_label.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/sub_ds_deepcopy.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/subnet_dns64_lookup.crpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/val_any_cap.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/val_canon_short_px.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/val_cnameother.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/val_global_quota.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/val_negcache_ds_nsec3.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/val_wcnsec_nods.rpl up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_transfer_limit.tdir/auth_transfer_limit.conf up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_transfer_limit.tdir/auth_transfer_limit.dsc up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_transfer_limit.tdir/auth_transfer_limit.post up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_transfer_limit.tdir/auth_transfer_limit.pre up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_transfer_limit.tdir/auth_transfer_limit.test up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_transfer_limit.tdir/auth_transfer_limit.testns up to 1.1.1.1
	external/bsd/unbound/dist/testdata/auth_transfer_limit.tdir/auth_transfer_limit.testns2 up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/example.com.zone up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/fast_reload_authdel.conf up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/fast_reload_authdel.conf2 up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/fast_reload_authdel.dsc up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/fast_reload_authdel.post up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/fast_reload_authdel.pre up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/fast_reload_authdel.test up to 1.1.1.1
	external/bsd/unbound/dist/testdata/fast_reload_authdel.tdir/fast_reload_authdel.testns up to 1.1.1.1
	external/bsd/unbound/dist/testdata/tcp_conn_limit_dec.tdir/tcp_conn_limit_dec.conf up to 1.1.1.1
	external/bsd/unbound/dist/testdata/tcp_conn_limit_dec.tdir/tcp_conn_limit_dec.dsc up to 1.1.1.1
	external/bsd/unbound/dist/testdata/tcp_conn_limit_dec.tdir/tcp_conn_limit_dec.post up to 1.1.1.1
	external/bsd/unbound/dist/testdata/tcp_conn_limit_dec.tdir/tcp_conn_limit_dec.pre up to 1.1.1.1
	external/bsd/unbound/dist/testdata/tcp_conn_limit_dec.tdir/tcp_conn_limit_dec.test up to 1.1.1.1
	external/bsd/unbound/dist/testdata/tcp_conn_limit_dec.tdir/tcp_conn_limit_dec.testns up to 1.1.1.1
	external/bsd/unbound/dist/README.md             up to 1.1.1.6
	external/bsd/unbound/dist/ax_pthread.m4         up to 1.1.1.3
	external/bsd/unbound/dist/config.guess          up to 1.10
	external/bsd/unbound/dist/config.h.in           up to 1.1.1.12
	external/bsd/unbound/dist/config.sub            up to 1.9
	external/bsd/unbound/dist/configure             up to 1.1.1.12
	external/bsd/unbound/dist/configure.ac          up to 1.1.1.12
	external/bsd/unbound/dist/cachedb/cachedb.c     up to 1.1.1.11
	external/bsd/unbound/dist/compat/getentropy_osx.c up to 1.1.1.3
	external/bsd/unbound/dist/compat/inet_pton.c    up to 1.1.1.2
	external/bsd/unbound/dist/compat/sha512.c       up to 1.1.1.6
	external/bsd/unbound/dist/daemon/cachedump.c    up to 1.1.1.9
	external/bsd/unbound/dist/daemon/daemon.c       up to 1.1.1.11
	external/bsd/unbound/dist/daemon/daemon.h       up to 1.1.1.8
	external/bsd/unbound/dist/daemon/remote.c       up to 1.1.1.12
	external/bsd/unbound/dist/daemon/remote.h       up to 1.1.1.7
	external/bsd/unbound/dist/daemon/stats.c        up to 1.1.1.12
	external/bsd/unbound/dist/daemon/worker.c       up to 1.1.1.12
	external/bsd/unbound/dist/daemon/worker.h       up to 1.1.1.5
	external/bsd/unbound/dist/dns64/dns64.c         up to 1.1.1.11
	external/bsd/unbound/dist/dnscrypt/dnscrypt.c   up to 1.1.1.7
	external/bsd/unbound/dist/dnscrypt/dnscrypt.h   up to 1.1.1.4
	external/bsd/unbound/dist/dnstap/dnstap.c       up to 1.1.1.9
	external/bsd/unbound/dist/dnstap/dnstap.h       up to 1.1.1.6
	external/bsd/unbound/dist/dnstap/dtstream.c     up to 1.1.1.7
	external/bsd/unbound/dist/dnstap/unbound-dnstap-socket.c up to 1.1.1.6
	external/bsd/unbound/dist/doc/Changelog         up to 1.1.1.12
	external/bsd/unbound/dist/doc/README            up to 1.1.1.12
	external/bsd/unbound/dist/doc/example.conf.in   up to 1.1.1.12
	external/bsd/unbound/dist/doc/libunbound.3.in   up to 1.1.1.12
	external/bsd/unbound/dist/doc/unbound-anchor.8.in up to 1.1.1.12
	external/bsd/unbound/dist/doc/unbound-checkconf.8.in up to 1.1.1.12
	external/bsd/unbound/dist/doc/unbound-control.8.in up to 1.1.1.12
	external/bsd/unbound/dist/doc/unbound-control.rst up to 1.1.1.3
	external/bsd/unbound/dist/doc/unbound-host.1.in up to 1.1.1.12
	external/bsd/unbound/dist/doc/unbound.8.in      up to 1.1.1.12
	external/bsd/unbound/dist/doc/unbound.conf.5.in up to 1.1.1.12
	external/bsd/unbound/dist/doc/unbound.conf.rst  up to 1.1.1.3
	external/bsd/unbound/dist/edns-subnet/addrtree.c up to 1.1.1.5
	external/bsd/unbound/dist/edns-subnet/subnetmod.c up to 1.1.1.11
	external/bsd/unbound/dist/ipsecmod/ipsecmod-whitelist.c up to 1.1.1.2
	external/bsd/unbound/dist/ipsecmod/ipsecmod.c   up to 1.1.1.7
	external/bsd/unbound/dist/ipset/ipset.c         up to 1.1.1.5
	external/bsd/unbound/dist/iterator/iter_delegpt.c up to 1.1.1.8
	external/bsd/unbound/dist/iterator/iter_delegpt.h up to 1.1.1.9
	external/bsd/unbound/dist/iterator/iter_donotq.c up to 1.1.1.2
	external/bsd/unbound/dist/iterator/iter_resptype.c up to 1.1.1.3
	external/bsd/unbound/dist/iterator/iter_resptype.h up to 1.1.1.3
	external/bsd/unbound/dist/iterator/iter_scrub.c up to 1.1.1.12
	external/bsd/unbound/dist/iterator/iter_scrub.h up to 1.1.1.3
	external/bsd/unbound/dist/iterator/iter_utils.c up to 1.1.1.11
	external/bsd/unbound/dist/iterator/iter_utils.h up to 1.1.1.10
	external/bsd/unbound/dist/iterator/iterator.c   up to 1.1.1.12
	external/bsd/unbound/dist/iterator/iterator.h   up to 1.1.1.9
	external/bsd/unbound/dist/libunbound/context.h  up to 1.1.1.7
	external/bsd/unbound/dist/libunbound/libunbound.c up to 1.1.1.10
	external/bsd/unbound/dist/libunbound/libworker.c up to 1.1.1.11
	external/bsd/unbound/dist/libunbound/libworker.h up to 1.1.1.4
	external/bsd/unbound/dist/libunbound/worker.h   up to 1.1.1.6
	external/bsd/unbound/dist/pythonmod/interface.i up to 1.1.1.11
	external/bsd/unbound/dist/pythonmod/pythonmod.c up to 1.1.1.9
	external/bsd/unbound/dist/respip/respip.c       up to 1.1.1.9
	external/bsd/unbound/dist/services/authzone.c   up to 1.7
	external/bsd/unbound/dist/services/authzone.h   up to 1.1.1.9
	external/bsd/unbound/dist/services/listen_dnsport.c up to 1.1.1.12
	external/bsd/unbound/dist/services/listen_dnsport.h up to 1.1.1.9
	external/bsd/unbound/dist/services/localzone.c  up to 1.1.1.11
	external/bsd/unbound/dist/services/localzone.h  up to 1.1.1.10
	external/bsd/unbound/dist/services/mesh.c       up to 1.1.1.12
	external/bsd/unbound/dist/services/mesh.h       up to 1.1.1.10
	external/bsd/unbound/dist/services/outside_network.c up to 1.1.1.12
	external/bsd/unbound/dist/services/outside_network.h up to 1.1.1.11
	external/bsd/unbound/dist/services/rpz.c        up to 1.1.1.7
	external/bsd/unbound/dist/services/cache/dns.c  up to 1.1.1.11
	external/bsd/unbound/dist/services/cache/rrset.c up to 1.1.1.9
	external/bsd/unbound/dist/sldns/keyraw.c        up to 1.1.1.7
	external/bsd/unbound/dist/sldns/str2wire.c      up to 1.1.1.10
	external/bsd/unbound/dist/smallapp/unbound-anchor.c up to 1.1.1.11
	external/bsd/unbound/dist/smallapp/unbound-checkconf.c up to 1.1.1.12
	external/bsd/unbound/dist/smallapp/worker_cb.c  up to 1.1.1.8
	external/bsd/unbound/dist/testcode/dohclient.c  up to 1.1.1.6
	external/bsd/unbound/dist/testcode/doqclient.c  up to 1.1.1.4
	external/bsd/unbound/dist/testcode/fake_event.c up to 1.1.1.11
	external/bsd/unbound/dist/testcode/testbound.c  up to 1.1.1.10
	external/bsd/unbound/dist/testcode/unitauth.c   up to 1.1.1.8
	external/bsd/unbound/dist/testcode/unitecs.c    up to 1.1.1.4
	external/bsd/unbound/dist/testcode/unitldns.c   up to 1.1.1.7
	external/bsd/unbound/dist/testcode/unitmain.c   up to 1.1.1.12
	external/bsd/unbound/dist/testcode/unittcpreuse.c up to 1.1.1.3
	external/bsd/unbound/dist/testcode/unitverify.c up to 1.1.1.10
	external/bsd/unbound/dist/testdata/auth_zonemd_xfr_chain_fail.rpl up to 1.1.1.2
	external/bsd/unbound/dist/testdata/dns_error_reporting.rpl up to 1.1.1.2
	external/bsd/unbound/dist/testdata/ipsecmod_hook.sh up to 1.1.1.2
	external/bsd/unbound/dist/testdata/iter_prefetch_fail.rpl up to 1.1.1.4
	external/bsd/unbound/dist/testdata/iter_privaddr.rpl up to 1.1.1.6
	external/bsd/unbound/dist/testdata/iter_resolve_minimised.rpl up to 1.1.1.6
	external/bsd/unbound/dist/testdata/iter_svcb_malformed.rpl up to 1.1.1.2
	external/bsd/unbound/dist/testdata/local_ds.rpl up to 1.1.1.3
	external/bsd/unbound/dist/testdata/stop_nxdomain_minimised.rpl up to 1.1.1.2
	external/bsd/unbound/dist/testdata/val_cnametonsec.rpl up to 1.1.1.4
	external/bsd/unbound/dist/testdata/val_cnametooptin.rpl up to 1.1.1.4
	external/bsd/unbound/dist/testdata/val_ds_cname.rpl up to 1.1.1.7
	external/bsd/unbound/dist/testdata/val_dsnsec.rpl up to 1.1.1.3
	external/bsd/unbound/dist/testdata/val_refer_unsignadd.rpl up to 1.1.1.6
	external/bsd/unbound/dist/testdata/val_referglue.rpl up to 1.1.1.7
	external/bsd/unbound/dist/testdata/val_secds_nosig.rpl up to 1.1.1.5
	external/bsd/unbound/dist/testdata/03-testbound.tdir/03-testbound.test up to 1.1.1.4
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/10-unbound-anchor.conf up to 1.1.1.2
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/10-unbound-anchor.test up to 1.1.1.2
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/petal.key up to 1.1.1.2
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/petal.pem up to 1.1.1.2
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/test_cert.key up to 1.1.1.2
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/test_cert.pem up to 1.1.1.2
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/127.0.0.1/no_more_keys.p7s up to 1.1.1.2
	external/bsd/unbound/dist/testdata/10-unbound-anchor.tdir/127.0.0.1/root.p7s up to 1.1.1.2
	external/bsd/unbound/dist/testdata/dnscrypt_cert.tdir/dnscrypt_cert.test up to 1.1.1.3
	external/bsd/unbound/dist/testdata/dnscrypt_cert_chacha.tdir/dnscrypt_cert_chacha.test up to 1.1.1.3
	external/bsd/unbound/dist/testdata/root_anchor.tdir/root_anchor.test up to 1.1.1.4
	external/bsd/unbound/dist/testdata/stat_values.tdir/stat_values.test up to 1.1.1.7
	external/bsd/unbound/dist/testdata/svcb.tdir/svcb.success-cases.zone up to 1.1.1.3
	external/bsd/unbound/dist/testdata/svcb.tdir/svcb.success-cases.zone.cmp up to 1.1.1.3
	external/bsd/unbound/dist/util/config_file.c    up to 1.1.1.12
	external/bsd/unbound/dist/util/config_file.h    up to 1.1.1.12
	external/bsd/unbound/dist/util/configlexer.c    up to 1.1.1.12
	external/bsd/unbound/dist/util/configlexer.lex  up to 1.1.1.12
	external/bsd/unbound/dist/util/configparser.c   up to 1.1.1.12
	external/bsd/unbound/dist/util/configparser.h   up to 1.1.1.12
	external/bsd/unbound/dist/util/configparser.y   up to 1.1.1.12
	external/bsd/unbound/dist/util/fptr_wlist.c     up to 1.1.1.11
	external/bsd/unbound/dist/util/fptr_wlist.h     up to 1.1.1.8
	external/bsd/unbound/dist/util/iana_ports.inc   up to 1.1.1.12
	external/bsd/unbound/dist/util/module.h         up to 1.1.1.10
	external/bsd/unbound/dist/util/net_help.c       up to 1.1.1.12
	external/bsd/unbound/dist/util/netevent.c       up to 1.10
	external/bsd/unbound/dist/util/netevent.h       up to 1.1.1.10
	external/bsd/unbound/dist/util/proxy_protocol.c up to 1.1.1.3
	external/bsd/unbound/dist/util/proxy_protocol.h up to 1.1.1.2
	external/bsd/unbound/dist/util/tube.c           up to 1.1.1.7
	external/bsd/unbound/dist/util/data/dname.c     up to 1.1.1.8
	external/bsd/unbound/dist/util/data/msgencode.c up to 1.1.1.11
	external/bsd/unbound/dist/util/data/msgparse.c  up to 1.1.1.10
	external/bsd/unbound/dist/util/data/msgreply.c  up to 1.1.1.12
	external/bsd/unbound/dist/util/data/msgreply.h  up to 1.1.1.12
	external/bsd/unbound/dist/util/data/packed_rrset.c up to 1.1.1.7
	external/bsd/unbound/dist/util/data/packed_rrset.h up to 1.1.1.8
	external/bsd/unbound/dist/util/shm_side/shm_main.c up to 1.1.1.7
	external/bsd/unbound/dist/validator/autotrust.c up to 1.1.1.9
	external/bsd/unbound/dist/validator/autotrust.h up to 1.1.1.4
	external/bsd/unbound/dist/validator/val_anchor.c up to 1.1.1.9
	external/bsd/unbound/dist/validator/val_neg.c   up to 1.1.1.9
	external/bsd/unbound/dist/validator/val_nsec.c  up to 1.1.1.8
	external/bsd/unbound/dist/validator/val_nsec.h  up to 1.1.1.6
	external/bsd/unbound/dist/validator/val_nsec3.c up to 1.1.1.8
	external/bsd/unbound/dist/validator/val_nsec3.h up to 1.1.1.7
	external/bsd/unbound/dist/validator/val_secalgo.c up to 1.1.1.9
	external/bsd/unbound/dist/validator/val_sigcrypt.c up to 1.1.1.11
	external/bsd/unbound/dist/validator/val_sigcrypt.h up to 1.1.1.7
	external/bsd/unbound/dist/validator/val_utils.c up to 1.1.1.8
	external/bsd/unbound/dist/validator/val_utils.h up to 1.1.1.8
	external/bsd/unbound/dist/validator/validator.c up to 1.1.1.12
	external/bsd/unbound/dist/validator/validator.h up to 1.1.1.8
	external/bsd/unbound/include/config.h           up to 1.18
	external/bsd/unbound/lib/libunbound/Makefile    up to 1.10
	external/bsd/unbound/lib/libunbound/shlib_version up to 1.10
	external/bsd/unbound/lib/libunbound/unbound.expsym up to 1.5
	distrib/sets/lists/base/shl.mi				1.1049
	distrib/sets/lists/debug/shl.mi				1.413

Import unbound 1.26.1
@
text
@a0 78
ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN SOA
SECTION ANSWER
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example.com. IN AXFR
SECTION ANSWER
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
example.com.	IN NS	ns.example.net.
www.example.com. IN A	1.2.3.4
example.com. IN SOA ns.example.com. hostmaster.example.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN SOA
SECTION ANSWER
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
example2.com.	IN NS	ns.example2.net.
EXTRA_PACKET
REPLY QR AA NOERROR
; too slow
ADJUST packet_sleep=5
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
extra.example2.com. IN A 1.2.3.5
EXTRA_PACKET
REPLY QR AA NOERROR
SECTION QUESTION
example2.com. IN AXFR
SECTION ANSWER
www.example2.com. IN A	1.2.3.4
example2.com. IN SOA ns.example2.com. hostmaster.example2.com. 1 3600 900 86400 3600
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id sleep=5
REPLY QR AA NOERROR
SECTION QUESTION
prim.example.net. IN A
SECTION ANSWER
prim.example.net. IN A 127.0.0.1
ENTRY_END

ENTRY_BEGIN
MATCH opcode qtype qname
ADJUST copy_id sleep=5
REPLY QR AA NOERROR
SECTION QUESTION
notif.example.net. IN A
SECTION ANSWER
notif.example.net. IN A 127.0.0.1
ENTRY_END
@


