head	1.1;
branch	1.1.1;
access;
symbols
	bind-2-20-29:1.1.1.2
	bind-9-20-27:1.1.1.1
	netbsd-11-0-RELEASE:1.1.1.1.2.2
	netbsd-11-0-RC7:1.1.1.1.2.2
	netbsd-11-0-RC6:1.1.1.1.2.2
	netbsd-11:1.1.1.1.0.2
	bind-9-20-24:1.1.1.1
	bind-9-20-23:1.1.1.1
	ISC:1.1.1;
locks; strict;
comment	@# @;


1.1
date	2026.05.20.16.42.57;	author christos;	state Exp;
branches
	1.1.1.1;
next	;
commitid	8F4FGV2ey5ZbCzGG;

1.1.1.1
date	2026.05.20.16.42.57;	author christos;	state Exp;
branches
	1.1.1.1.2.1;
next	1.1.1.2;
commitid	8F4FGV2ey5ZbCzGG;

1.1.1.2
date	2026.09.17.17.45.00;	author christos;	state Exp;
branches;
next	;
commitid	6QdcGjuUmo5e60WG;

1.1.1.1.2.1
date	2026.05.20.16.42.57;	author martin;	state dead;
branches;
next	1.1.1.1.2.2;
commitid	kM4MXv6L08MweqLG;

1.1.1.1.2.2
date	2026.06.27.10.14.01;	author martin;	state Exp;
branches;
next	;
commitid	kM4MXv6L08MweqLG;


desc
@@


1.1
log
@Initial revision
@
text
@options {
	directory ".";
};

view chaos ch {
        match-clients { any; };
        recursion yes;
        zone "." {
                type hint;
                file "chaos.hints";
        };
};
@


1.1.1.1
log
@
Import bind 9.20.23 (previous was 9.20.22)

Security Fixes
Limit resolver server list size. (CVE-2026-3592)

When resolving a domain with many nameservers that shared overlapping
IP addresses (e.g., 10 NS records all pointing at the same set of
addresses), BIND could previously waste time querying duplicate
addresses and build up excessively large server lists. Addresses
in the resolver's server list are now deduplicated so that each
unique IP is only queried once per resolution attempt, regardless
of how many NS records point to it. The number of addresses stored
per nameserver name is also now capped at six (combined A and AAAA),
preventing memory and CPU overhead from domains with unusually
large NS/glue sets.

ISC would like to thank Shuhan Zhang from Tsinghua University for
reporting this issue. [GL #5641]

Fix GSS-API resource leak. (CVE-2026-3039)

A memory leak was fixed where each GSS-API TKEY negotiation leaked
a security context inside the GSS library. An unauthenticated
attacker could exhaust server memory by sending repeated TKEY
queries to a server with tkey-gssapi-keytab configured. The leaked
memory was allocated by the GSS library, bypassing BIND's memory
accounting.

Multi-round GSS-API negotiation (GSS_S_CONTINUE_NEEDED) is now
rejected, as BIND never supported it correctly and Kerberos/SPNEGO
completes in a single round.

ISC would like to thank Vitaly Simonovich for bringing this
vulnerability to our attention. [GL #5752]

Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)

Recursion, dynamic updates (UPDATE), and zone change notifications
(NOTIFY) are now disabled for views with a class other than IN
(such as CHAOS or HESIOD); authoritative service for non-IN zones
(e.g. version.bind in class CHAOS) continues to work as before.
Servers configured with recursion yes; in a non-IN view log a
warning at startup, and named-checkconf flags the same condition.
UPDATE and NOTIFY messages that specify the meta-classes ANY or
NONE in the question section are now rejected with FORMERR.

This addresses a set of closely related security issues collectively
identified as CVE-2026-5946. ISC would like to thank Mcsky23 for
bringing these issues to our attention. [GL #5784]

Avoid unbounded recursion loop. (CVE-2026-5950)

A bug during bad server handling could cause the resolver to enter
an infinite loop, continuously sending queries to an upstream server
with no exit condition, until the resolver query timeout was hit.
This has been fixed.

ISC would like to thank Billy Baraja (BielraX) for bringing this
issue to our attention. [GL #5804]

dfmt: Command not found.

A resolver could crash when handling a SIG(0)-signed response if
the matching client query was cancelled while signature verification
was still in progress for example, when the recursive-clients
quota was exhausted. This has been fixed.

ISC would like to thank Naoki Wakamatsu for bringing this vulnerability
to our attention. [GL #5819]

Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2
SETTINGS frames. (CVE-2026-3593)

Previously, a use-after-free vulnerability in the DNS-over-HTTPS
implementation could cause named to crash when a client sent a
flood of HTTP/2 SETTINGS frames while a DoH response was being
written. This affected servers with DoH (DNS-over-HTTPS) enabled
and has been fixed.

ISC would like to thank Naresh Kandula Parmar (Nottiboy) for
reporting this. [GL #5755]

Fix outgoing zone transfers' quota issue.

Unauthorized clients could consume the entire outgoing zone-transfer
quota and block authorized zone transfer clients. This has been
fixed. [GL #3589]

Feature Changes
Fix CPU spikes and slow queries when cache approaches memory limit.

Cache cleanup is now spread probabilistically to avoid CPU usage
spikes and a drop in query throughput. [GL #5891]

Bug Fixes
Use the zone file's basename as origin in DNSSEC tools.

In dnssec-signzone and dnssec-verify, when the zone origin is not
specified using the -o parameter, the default behavior is to try
to sign using the zone's file name as the origin. So, for example,
dnssec-signzone -S example.com will work, so long as the file name
matches the zone name.

This now also works if the zone is in a different directory. For
example, dnssec-signzone -S zones/example.com will set the origin
value to example.com. [GL #5678]

Fix a possible race condition during zone transfers.

The named process could terminate unexpectedly when processing an
IXFR message during a zone transfer. This has been fixed. [GL #5767]

Fix named crash when processing SIG records in dynamic updates.

Previously, named could abort if a client sent a dynamic update
containing a SIG record (the legacy signature type) to a zone
configured with an update-policy. The function dns_db_findrdataset
had an incorrect requirements prerequisite that prevented SIG
records from being looked up, which was triggered as part of
processing an UPDATE request and could be triggered remotely by
any client permitted to send updates. This has been fixed by ensuring
that SIG records are handled consistently with RRSIG records during
update processing. [GL #5818]

Fix rndc modzone behavior for a zone in named.conf.

If a zone was present in the configuration file and not originally
added by rndc addzone, rndc modzone for that zone would succeed
once but subsequent rndc modzone attempts would fail. This has been
fixed. [GL #5826]

Fix zone verification of NSEC3 signed zones.

Previously, when computing the compressed bitmap during verification
of an NSEC3-signed zone, an undersized buffer was used that resulted
in an out-of-bounds write if there were too many active windows in
the bitmap. This impacted the mirror zones which are NSEC3-signed,
dnssec-signzone and dnssec-verify. This has been fixed. [GL #5834]

Prevent a crash when using both dns64 and filter-aaaa.

An assertion failure could be triggered if both dns64 and the
filter-aaaa plugin were in use simultaneously. This happened if
the plugin triggered a second recursion process, which then attempted
to store DNS64 state information in a pointer that had already been
set by the original recursion process. This has been fixed. [GL
#5854]

Fixed an assertion failure when processing catalog zones.

If a TXT record containing an invalid name TSIG key name was found
when processing a catalog zone member's primaries definition,
dns_name_free was incorrectly called, triggering an assertion. This
has been fixed. [GL #5858]

Prevent malicious DNSSEC zones from exhausting validator CPU.

A DNSSEC-signed zone could publish a DNSKEY with an unusually large
RSA public exponent and force any validator resolving names in that
zone to spend disproportionate CPU verifying signatures. The
validator now rejects such DNSKEYs, matching the limit already
applied to keys read from files or HSMs. [GL #5881]

Fix rndc-confgen aborting on HMAC-SHA-384/512 keys above 512 bits.

rndc-confgen (with either -A hmac-sha384 or -A hmac-sha512) previously
documented a -b range of 1..1024, but any value above 512 aborted
on hardened builds instead of producing a key. The full advertised
range now works. [GL #5903]

Prevent crafted queries from degrading RRL performance.

With response rate limiting enabled, an attacker sending queries
from many spoofed source addresses could steer entries into the
same slot of the internal rate-limit table and slow down query
processing on the affected server. The table now uses a per-process
keyed hash so the placement of entries cannot be predicted or
influenced from the network. [GL #5906]

Prevent rare named crash when notifies are cancelled.

Under heavy load, named could occasionally crash when a queued
outbound notify or zone refresh was cancelled at the moment it was
being sent for example, while a zone was being reloaded or removed.
The race that caused the crash is now prevented. [GL #5915]

Stop delv from aborting on a malformed query name.

delv previously aborted with SIGABRT instead of exiting cleanly
when given a query name that failed wire-format conversion (e.g.
a label longer than 63 octets). After this change delv prints the
parse error and exits with a normal failure code. [GL #5916]

Fix a crash when reconfiguring while an NTA is being rechecked.

Previously, if named was reconfigured or shut down while a negative
trust anchor was being rechecked against authoritative servers,
the in-flight recheck could outlive the view that owned it and
cause named to crash. This has been fixed. [GL #5938]

Fix a bug in allow-query/allow-transfer catalog zone custom properties.

The named process could terminate unexpectedly when processing a
catalog zone with an invalid allow-query or allow-transfer custom
property (i.e. having a non-APL type) coexisting with the valid
property. This has been fixed. [GL #5941]

Fix a memory leak issue in catalog zones.

The named process could leak small amounts of memory when processing
a catalog zone entry which had defined custom primary servers with
TSIG keys, if both the regular primaries custom property syntax
and the legacy alternative syntax (masters) were used at the same
time. This has been fixed. [GL #5943]

Fix suppressed missing-glue check in named-checkzone.

named-checkzone and named-checkconf -z silently skipped the
missing-glue check for any NS name that had already triggered an
extra-AAAA-glue warning, so zones missing required A glue could
pass validation and be deployed with broken delegations. [GL !11899]

Implement seamless outgoing TCP connection reuse.

The resolver can and will reuse outgoing TCP connections to the
same host, as recommended by RFC 7766. This prevents a whole class
of attacks that abuse the fact that establishing a TCP connection
is expensive and it is fairly easy to deplete the outgoing TCP
ports by putting them into TIME_WAIT state.

The number of pipelined queries per connection is capped at 256 to
limit the impact of a connection drop. [GL !11845]

Reject record sets too large to serve in DNS.

When BIND was asked to store a record set whose total size exceeded
what fit in a DNS message, it would allocate memory and build the
structure, then fail later at response time. Such oversized record
sets are now rejected at the time of storage with an error, avoiding
wasted work on data that can never be served. [GL !11963]
@
text
@@


1.1.1.2
log
@Import bind-9.20.29 (previous was 9.20.27)

BIND 9.20.29
Security Fixes
[CVE-2026-19668] Prevent excessive CPU use validating crafted DNSSEC
responses. a0a61dba9e
  A malicious authoritative server could serve a securely delegated zone
  whose DS and DNSKEY records carry many distinct key tags but no valid
  match, forcing a validating resolver into excessive key-tag matching
  and high CPU use for every query. BIND now bounds this work with the
  per-query validation limit (max-validations-per-fetch). [GL #5349]

[CVE-2026-19033] Require a TSIG on every message of incoming zone
transfers. 9404cd2b8c
  BIND 9 used to accept TSIG-signed zone transfers in which some messages
  were unsigned, and processed those messages before the next signature
  could vouch for them. It now requires a TSIG on every message of an
  incoming AXFR or IXFR; all modern nameserver already sign every message,
  so no change is expected in practice. [GL #6062]

[CVE-2026-77119] Prevent a DNSSEC downgrade of secure delegations via
unrelated NSEC3. 3bed9c8e9e
  A validating resolver could be tricked into treating a secure delegation
  as unsigned and accepting forged answers for names beneath it, if an
  attacker could inject responses to its queries. Such forged proofs are now
  rejected. [GL #6234]

[CVE-2026-19941] Prevent forged DNSSEC-validated NXDOMAIN
responses. a36bf58daf
  A validating resolver could accept a signed NSEC record from an unrelated
  zone as proof that a wildcard did not exist. An on-path attacker or
  malicious forwarder controlling a signed zone could therefore forge an
  authenticated NXDOMAIN response for a name that should resolve through
  a wildcard. BIND now requires the wildcard-denial and name-nonexistence
  proofs to be signed by the same zone. [GL #6253]

[CVE-2026-19666] DNS64 with break-dnssec could cause an assertion
failure. 4cec4965c4
  When a "dns64" statement is configured with "break-dnssec yes" and its
  "exclude" list matches some but not all of the addresses in an AAAA RRset,
  named removes the excluded addresses from the answer instead of
  synthesizing new ones. If the answer being filtered had been cached
  together with a proof that the queried name does not exist -- which is what
  a wildcard match produces -- named terminated with an assertion failure.
  Only recursive resolvers are affected, and only when "break-dnssec yes"
  is in use; the answer has to come from the cache, so a server that is only
  authoritative cannot reach this. [GL #6301]

[CVE-2026-19667] Reject negative cache records that do not fit in a
dns_rdata_t. dbf08c8581
  A single crafted response from a server could make a resolver cache a
  malformed negative entry and then terminate with an assertion failure when
  reading it back. Only recursive resolvers are affected, on a default
  configuration. [GL #6302]

[CVE-2026-19662] Prevent resolver crash with cached DNSSEC
proofs. c884cc1ba0
  Under certain timing conditions, concurrent recursive queries could cause
  named to crash when cached DNSSEC NOQNAME proof data was replaced while
  still in use. Cached proof data is now retained until all queries using
  it have completed. [GL #6333]

[CVE-2026-75029] Discard repeated SOA, CNAME, and DNAME records when
parsing DNS messages. 0d630758c2
  A DNS message could carry the same SOA, CNAME, or DNAME record many
  times, and named kept every copy while parsing it. With name compression
  those copies took up far more memory internally than in the message
  itself, and every later processing step had to handle all of them. named
  now keeps the first copy of such a record and discards identical
  repeats. [GL #6335]

[CVE-2026-77692] Fix an unauthenticated crash on HTTPS using
SIG(0) 5a24401c5c
  A specifically crafted HTTPS query using SIG(0) as authentication could
  crash named if the client closes the connection before named actually
  verifies the signature. This is now fixed. [GL #6343]

[CVE-2026-81736] Cached HTTPS/SVCB aliases could exhaust resolver
CPU. 20bbb1639a
  A recursive resolver that had cached a large set of interlinked HTTPS
  or SVCB records in alias form could be driven to do an excessive amount
  of work assembling a single response, because it followed every cached
  alias target when building the additional section. A client permitted
  to use recursion, together with an attacker-controlled zone used to
  plant the records, could repeat small queries to consume enough CPU to
  delay or deny service to other clients. The amount of additional
  processing done for one query is now bounded. [GL #6347]

[CVE-2026-76163] Prevent TKEY queries from terminating named without global
options. 7645138538
  named could terminate unexpectedly when a remote client sent a TKEY
  query if the configuration did not include a global options statement.
  This has been fixed.
  ISC thanks Owais Lone (thesecguy) for reporting the issue. [GL #6357]

[CVE-2026-78301] Out-of-zone records in a zone database could be served as
authoritative. 72a10c3a0b
  When a zone database contained records for names outside the zone -- such
  as a delegation above the zone apex, left behind by a secondary that had
  accepted out-of-zone data from its primary -- the server could treat them
  as authoritative and answer queries for names inside the zone with that
  out-of-zone data instead of the zone's own. A server that was also a
  resolver could follow such a delegation and cache the answers of the
  server it named, affecting names outside the configured zone. Zone
  database lookups are now confined to names at or below the zone's
  origin.
  ISC would like to thank Henrique Pereira for reporting the
  issue. [GL #6361]

[CVE-2026-80274] Crash on wildcard answers carrying both NSEC and NSEC3
proofs. 0e44451b1a
  When a wildcard answer arrived with both NSEC and NSEC3 records at the
  name proving that the queried name does not exist, the resolver could
  pick different records when caching the answer and when retrieving the
  proof, depending on the order in which the authoritative server sent
  them. This could terminate named with an assertion failure, fail the
  query with SERVFAIL, or serve a denial record other than the one that
  had been verified. The resolver now caches and serves the same denial
  record it accepted when the answer was received.
  ISC would like to thank hythyt for reporting the issue. [GL #6369]

[CVE-2026-81563] Following HTTPS/SVCB aliases could leak resolver cache
memory. 3162df369e
  When a recursive server answered a query for an HTTPS or SVCB record in
  alias form and the alias target had more than 13 records, the target
  records were pinned in the cache permanently instead of being released
  once the answer was sent. A remote party who could make the server follow
  such aliases to a steady stream of fresh names could grow the cache
  beyond the configured max-cache-size until the server was unable to
  resolve unrelated names. The records are now released
  correctly.
  ISC would like to thank Samy Medjahed/Ap4sh for reporting the
  issue. [GL #6374]

New Features
Add an agent skill for the isc_job/isc_async/isc_work APIs. fe32990b06
  Documents when to use isc_job_run(), isc_async_run() or
  isc_work_enqueue(), and the contract each one imposes. No functional
  change. [GL !12561]

Removed Features
Remove unused closest encloser proof caching. abd8b5bfd8
  BIND used to cache an NSEC3 closest encloser proof alongside positive
  wildcard answers so that a resolver could re-send it when answering
  from its cache. That stopped being used in BIND 9.9 (2011), when
  positive wildcard responses were changed to omit that NSEC3 record --
  RFC 5155 requires only the next closer name proof -- and the closest
  encloser came to be derived during validation instead. The caching code
  has been unreachable ever since, so this removes it with no change in
  behaviour. [GL #5803] [GL !12660]

Feature Changes
Reject oversized and malformed DNSKEY records up front. 6c22109924
  Oversized RSA key material in a DNSKEY record was only rejected after it
  had been converted, allocating memory proportional to the record size.
  Such records are now rejected before conversion, as are Ed25519 and
  Ed448 keys with trailing bytes that were previously silently
  ignored. [GL #4537] [GL !12560]

Bug Fixes
Prevent a crash when using both dns64 and filter-a. bce5d10d18
  An assertion failure was possible when using both dns64 and the
  filter-a plugin simultaneously; this has been fixed. [GL #5979] [GL !12663]

Fix update-policy grant external address passing. b1e955c326
  Only TCP client addresses are supposed to be passed to an external
  handler for the associated update-policy rule, but UDP client addresses
  were also being passed. This could have caused the external handler to
  return a result it otherwise wouldn't. This has been fixed. [GL #6061]
  [GL !12555]

Missing required NSEC3 for delegation not detected. e84ed2e9d7
  A missing required NSEC3 record for an insecure delegation in a non
  OPTOUT range was not being detected. This has been fixed. [GL #6063]
  [GL !12611]

Tighten EUI48 and EUI48 text parsing. ff50f2cdf1
  Malformed EUI48 and EUI64 records could be accepted. This has been
  fixed. [GL #6082] [GL !12521]

GeoIP ACL state can be stale or wrong after reload. 63baf425b3
  named caches GeoIP information after looking it up, but the cached
  information was not invalidated when the GeoIP database was reloaded, so
  it could continue to be used. We now invalidate existing cached GeoIP
  information as part of the reloading process. [GL #6083] [GL !12662]

Honor DNSSEC policy key tag ranges. b82e5834b7
  When a DNSSEC policy configured a non-default tag-range, dnssec-keygen and
  dnssec-ksr could accept generated keys outside that range. Both tools
  now honor the configured minimum and maximum key tags. [GL #6091]
  [GL !12549]

Fix double free in mdig when EDNS options are specified. af5bd0b0ff
  When the default_query is cloned the EDNS options need to be cloned
  rather than the pointer copied. The old behaviour results in a double
  free of the options. This has been fixed. [GL #6095] [GL !12661]

Fix a crash when an IXFR falls back to AXFR with updates still
pending. e34062bc7e
  When a secondary zone received an incremental transfer (IXFR) and the
  primary then caused named to fall back to a full transfer (AXFR) while
  some of the already-received incremental changes were still waiting to be
  applied, named could later crash when that transfer finished. The pending
  changes are now discarded correctly before the AXFR retry. [GL #6114]
  [GL !12624]

Fix DS requests to parental agents over TLS. 55830d30f6
  TLS configuration for parental agents was being ignored when sending DS
  requests. This has been fixed. [GL #6135] [GL !12613]

Fix a crash when resolving names below a cached DNAME. b94e940f52
  A recursive resolver could crash when it answered a query for a name
  beneath a cached DNAME while that same DNAME record was concurrently
  refreshed or evicted from the cache. [GL #6182] [GL !12593]

Rndc-confgen -q (quiet) option is documented but doesn't work. 7e4a7ca1a7
  The command line parsing in rndc-confgen was broken so rndc-confgen -q
  did not work. This has been fixed. [GL #6187] [GL !12575]

Enforce query ACLs for redirect zones and searched DLZs. bc69876b2e
  Queries answered from redirect zones or searched DLZ databases did not
  consistently honor allow-query and allow-query-on, potentially exposing
  restricted DNS data to excluded clients or through excluded listening
  addresses. These ACLs are now enforced before redirect or DLZ data is
  returned. [GL #6251], #6252 [GL !12646]

Check "asnum" validity in GeoIP ACLs. 28c2bfdc7b
  We now check the validity of autonomous system (AS) numbers when parsing
  GeoIP ACLs that use asnum elements at configuration time.
  asnum values start with an optional case-insensitive "AS" prefix,
  followed only by decimal digits, with no spaces or other extraneous
  characters. The value represented cannot exceed 2^32. [GL #6255]
  [GL !12511]

Prevent crashes while reporting DNSSEC signing statistics. c190514f0a
  Servers with zone-statistics full could terminate while reporting
  DNSSEC signing statistics for a zone tracking adding more than four
  signing keys. [GL #6256] [GL !12674]

Fix various nits in the netmgr code. c28cdad51b
  The MR consists of couple of small fixes and uncaught errors in the
  Network Manager. [GL #6257] [GL !12576]

Fix a crash on remote-servers lists that reference themselves. aaae614f9d
  Since 9.21.16 and 9.20.17, a remote-servers, primaries, masters, or
  parental-agents list that referenced itself, directly or through
  another list, made named crash on startup or reconfiguration. Such
  references are again skipped and the remaining entries in the list are
  used, as in earlier versions. [GL #6287] [GL !12604]

A record from outside a response policy zone could stop named. d135513b37
  A response policy zone transferred from a primary can contain a record
  whose name lies outside the zone. Such a record could stop named, both
  when it arrived and again at every startup afterwards, because a
  secondary keeps it in its own copy of the zone. Records like this are now
  rejected and logged; previously one could also silently create a policy
  entry for an unrelated name. [GL #6304] [GL !12543]

"rndc flushtree ." failed to flush the cache. 96e8b585ed
  rndc flushtree flushes cache data below a specified name. If the name
  specified is the DNS root, it should fully empty the cache, the same as
  rndc flush. However, there was a bug causing the command, in that case,
  to have no effect on the cache at all; this has been fixed. [GL #6308]
  [GL !12582]

Invalid key-store configuration could abort the DNSSEC tools. 1d796ab072
  Invalid configured key-stores named "key-directory" in configuration
  files could abort the DNSSEC tools. This has been fixed. [GL #6313]
  [GL !12653]

NSEC signature set could bypass the secure-delegation check. c966177f6c
  When proving that a delegation is insecure, the validator bounded an
  NSEC record's authority by the signer of whichever RRSIG happened to
  come first in the record's signature set, rather than the signature that
  actually verified. A grandparent NSEC padded with an extra, unverifiable
  signature could therefore pass the check that keeps such proofs from
  reaching below a signed child zone. The validator now requires every
  signature on the NSEC to name the same signer and refuses proofs whose
  signature set is malformed or larger than max-validations-per-fetch
  allows. [GL #6321]

Fix a possible nsupdate issue when using GSS-TSIG. 4ddcab2d3c
  The nsupdate process could terminate unexpectedly when using the
  GSS-TSIG mode executed with the nsupdate -g option. This has been
  fixed. [GL #6325] [GL !12588]

Fix isccc_alist_define error paths. af1349552a
  If there is an out of memory error in isccc_alist_define a memory leak
  (the sexpr holding the key name) or a double free (value) could occur.
  This has been fixed. [GL #6329] [GL !12636]

Check for empty 'endpoints' list. 23f58af443
  Configuring an http block with endpoints {}; previously caused a crash
  in named. This is now rejected earlier by the configuration check.
  [GL #6330] [GL !12552]

Named could crash with a single-element geoip sortlist. 0e996a4d3b
  If named was configured with a single-element sortlist containing a geoip
  ACL element, any matching query triggered an assertion failure. This
  has been fixed. [GL #6342] [GL !12583]

Prevent out-of-bailiwick CNAMEs from evicting cached records. cdedd4acd5
  A recursive resolver could remove valid cached records when a DNS
  response contained an out-of-bailiwick CNAME with the same owner name.
  Out-of-bailiwick data is now discarded before it can modify the
  cache. [GL #6345] [GL !12651]

Restore periodic cleanup of stale resolver address data. 356f4013f8
  Stale resolver address data could remain cached until memory pressure or
  an explicit flush. Correct the cleanup interval so it is removed
  periodically. [GL #6346] [GL !12589]

Fix named-checkconf/named crash with malformed key name. 9f218f6aaf
  When a primary/remote-server key name was malformed, named-checkconf and
  named were both crashing (after warning about the invalid key name).
  This is now fixed. [GL #6362] [GL !12639]

Fix -Wformat-truncation warning in totext_in_wks() f97c2bea40
  BIND 9 failed to build with GCC 16 at -O3: rendering a WKS record as
  text triggered a -Wformat-truncation error, which is fatal in developer
  builds. The port number is now printed with a 16-bit format specifier,
  so the compiler can see it always fits the output buffer. [GL !12542]

Fix off-by-one errors caused by magic hardcoded values. 726c6cb795
  Fix off-by-one comparinson errors: "named -p http=" dropped the first
  digit of the given port (for example, "http=8080" selected port 80) and
  now uses the port as given, and "named-rrchecker -C" compared only part
  of the "CLASS" prefix when filtering generic class names, which was
  harmless in practice but is now corrected. [GL !12616]

Hmac_verify() now accepts truncated HMACs only when requested. c81b111496
  The hmac_verify() function incorrectly compares only up to
  'sig->length' bytes, but the signature and its length should not be
  trusted, e.g. in case if it comes from a user query.
  Don't accept signatures which length isn't equal to the expected
  calculated HMAC length unless it is explicitly requested by the caller,
  e.g. for truncated TSIG [1] support.
  [1] https://datatracker.ietf.org/doc/html/rfc8945#name-tsig-truncation
  -policy [GL !12629]

Prevent resolver crashes while processing DNS over TCP. 81b3b6d89f
  Recursive resolvers could terminate with an assertion failure while
  processing DNS responses over TCP under sustained traffic. The failure
  was observed on resolvers configured globally with forward only; the
  same transport path is also used by iterative resolution. This has been
  fixed. [GL !12537]
@
text
@d6 6
a11 6
	match-clients { any; };
	recursion yes;
	zone "." {
		type hint;
		file "chaos.hints";
	};
@


1.1.1.1.2.1
log
@file warn-chaos-recursion.conf was added on branch netbsd-11 on 2026-06-27 10:14:01 +0000
@
text
@d1 12
@


1.1.1.1.2.2
log
@Pull up the following, requested by christos in ticket #315:

	external/mpl/bind/dist/bin/tests/system/class/ns1/chaos.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/ns2/example.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/ns2/localhost.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/ns2/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/setup.sh up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/tests_class_chaos.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/tests_class_update.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/class/ns3/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/cap_glues/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/cap_glues/ns1/root.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/cap_glues/ns2/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/cap_glues/ns2/tld.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/cap_glues/tests_cap_glues.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/cap_glues/ns3/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/cap_glues/ns3/root.hint up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/catz/ns1/catalog-bad6.example.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/checkconf/warn-chaos-recursion.conf up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/checkconf/inline-inherit.conf up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/zones/delegations.partial.db.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/zones/ns.partial.db.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/zones/root.db.j2.manual up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/zones/soa.partial.db.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/zones/template.db.j2.manual up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/controls.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/root.hint.conf up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/_common/zones.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec/signer/general/test13.zone up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/masterformat/ns2/named.args up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/nsupdate/ans11/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/nsupdate/tests_update_sig.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns10/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns10/redirect.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns10/root.hints up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns7/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns7/redirect.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns7/root.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns8/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns8/root.hints up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/tests_redirect_dns64.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns9/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns9/redirect.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns9/root.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/redirect/ns9/sign.sh up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tcp/ns2/named.args up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tcp/ns3/named.args up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tcp/ns4/named.args up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tcp/ns5/named.args up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/ans.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/xfer/ans11/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/xferquota/ns3/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/xferquota/ns3/quota.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/xferquota/ns3/root.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dispatch/ans4/tcp-only.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dispatch/ans4/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dispatch/tests_tcponly.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/kasp/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/kasp/ns1/root.db.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/kasp/ns1/setup.sh up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dns64_dname/ns1/hack.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dns64_dname/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dns64_dname/ns1/root.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dns64_dname/ns2/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dns64_dname/ns2/root.hint up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dns64_dname/tests_dns64_dname.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_cname_response/ans2/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_cname_response/ans2/example.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_cname_response/ans2/secure.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_cname_response/tests_cname_rejection.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_cname_response/ns3/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_cname_response/ns3/trusted.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/ns2/truncated-active.selfsigned.db.signed up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/ns2/truncated-revoked.selfsigned.db.signed up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/doth/tests_malicious.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/isctest/transfer.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/nsec_ixfr/ns1/example.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/nsec_ixfr/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/nsec_ixfr/ns2/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/nsec_ixfr/setup.sh up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/nsec_ixfr/tests_nsec_ixfr.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/resend_loop/ans3/ans.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/resend_loop/tests_resend_loop.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/resend_loop/ns4/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/resend_loop/ns4/root.hint up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/rndc_confgen/tests_rndc_confgen.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/mismatchtcp/ans2/example.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/mismatchtcp/ans2/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/mismatchtcp/tests_mismatchtcp.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/mismatchtcp/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/mismatchtcp/ns1/root.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/qpcache_rrsig_any/ans3/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/qpcache_rrsig_any/tests_qpcache_rrsig_any.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/qpcache_rrsig_any/ns2/named.args up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/qpcache_rrsig_any/ns2/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns1/root.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns2/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns2/tld.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/tests_selfpointedglue.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns3/example.tld.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns3/example2.tld.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns3/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns4/named.args.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns4/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/selfpointedglue/ns4/root.hint up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/srtt_ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/README up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ans2/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/tests_srtt.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ans3/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ans4/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ans5/ans.py up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ns1/root.db up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ns6/named.args up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/srtt/ns6/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tkeyleak/ns1/dns.keytab up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tkeyleak/ns1/example.db.in up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tkeyleak/ns1/named.conf.j2 up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tkeyleak/prereq.sh up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tkeyleak/setup.sh up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/tkeyleak/tests_tkeyleak.py up to 1.1.1.1
	external/mpl/bind/dist/doc/notes/notes-9.20.23.rst up to 1.1.1.2
	external/mpl/bind/dist/doc/notes/notes-9.20.24.rst up to 1.1.1.1
	external/mpl/bind/dist/doc/changelog/changelog-9.20.23.rst up to 1.1.1.1
	external/mpl/bind/dist/doc/changelog/changelog-9.20.24.rst up to 1.1.1.1
	external/mpl/bind/dist/bin/tests/system/ans.pl  delete
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/ns2/truncated.selfsigned.db.signed delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/badkeydata delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/badmessageid delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/ednsformerr delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/ednsnotimp delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/goodaxfr delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/ixfrnotimp delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/partial delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/soamismatch delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/unknownkey delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/unsigned delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/wrongkey delete
	external/mpl/bind/dist/bin/tests/system/xfer/ans5/wrongname delete
	external/mpl/bind/dist/CONTRIBUTING.md          up to 1.1.1.11
	external/mpl/bind/dist/NEWS                     up to 1.1.1.9
	external/mpl/bind/dist/configure                up to 1.25
	external/mpl/bind/dist/configure.ac             up to 1.1.1.23
	external/mpl/bind/dist/srcid                    up to 1.1.1.24
	external/mpl/bind/dist/bin/check/check-tool.c   up to 1.13
	external/mpl/bind/dist/bin/confgen/keygen.c     up to 1.9
	external/mpl/bind/dist/bin/delv/delv.c          up to 1.20
	external/mpl/bind/dist/bin/dnssec/dnssec-keygen.c up to 1.17
	external/mpl/bind/dist/bin/dnssec/dnssec-ksr.c  up to 1.6
	external/mpl/bind/dist/bin/dnssec/dnssec-signzone.c up to 1.18
	external/mpl/bind/dist/bin/dnssec/dnssec-verify.c up to 1.11
	external/mpl/bind/dist/bin/named/bind9.xsl      up to 1.1.1.13
	external/mpl/bind/dist/bin/named/controlconf.c  up to 1.15
	external/mpl/bind/dist/bin/named/main.c         up to 1.24
	external/mpl/bind/dist/bin/named/server.c       up to 1.29
	external/mpl/bind/dist/bin/named/statschannel.c up to 1.20
	external/mpl/bind/dist/bin/nsupdate/nsupdate.rst up to 1.1.1.7
	external/mpl/bind/dist/bin/tests/system/conftest.py up to 1.1.1.9
	external/mpl/bind/dist/bin/tests/system/feature-test.c up to 1.15
	external/mpl/bind/dist/bin/tests/system/packet.pl up to 1.1.1.5
	external/mpl/bind/dist/bin/tests/system/requirements.txt up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/start.pl up to 1.1.1.13
	external/mpl/bind/dist/bin/tests/system/_common/controls.conf.in up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/_common/rndc.conf up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/_common/rndc.key up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/_common/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/_common/root.hint.blackhole up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/_common/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/additional/ns3/root.hint up to 1.1.1.4
	external/mpl/bind/dist/bin/tests/system/allow_query/tests.sh up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/tests_sh_allow_query.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/controls.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named02.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named03.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named04.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named05.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named06.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named07.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named08.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named09.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named10.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named11.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named12.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named21.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named22.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named23.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named24.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named25.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named26.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named27.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named28.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named29.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named30.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named31.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named32.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named33.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named34.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named40.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named53.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named54.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named55.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named56.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/allow_query/ns2/named57.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/catz/tests.sh up to 1.1.1.14
	external/mpl/bind/dist/bin/tests/system/catz/ns1/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/catz/ns2/named.conf.j2 up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/chain/ns7/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/checkconf/tests.sh up to 1.1.1.15
	external/mpl/bind/dist/bin/tests/system/checkds/tests_checkds.py up to 1.1.1.8
	external/mpl/bind/dist/bin/tests/system/checknames/ns2/root.hints up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/checknames/ns3/root.hints up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/checknames/ns4/root.hints up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/checknames/ns5/root.hints up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/cipher_suites/tests_cipher_suites.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/cookie/cookie_ans.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/cookie/ns1/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/cookie/ns3/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/cookie/ns4/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/cookie/ns5/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/cookie/ns6/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/dialup/tests_dialup_zone_transfer.py up to 1.1.1.5
	external/mpl/bind/dist/bin/tests/system/digdelv/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/digdelv/tests.sh up to 1.1.1.20
	external/mpl/bind/dist/bin/tests/system/dispatch/ns1/root.db up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/dnssec/tests.sh up to 1.1.1.18
	external/mpl/bind/dist/bin/tests/system/dnssec/tests_sh_dnssec.py up to 1.1.1.6
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/tests_malformed_dnskey.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/ns2/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/ns2/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/ns3/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/dnssec_malformed_dnskey/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/emptyzones/ns1/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/expiredglue/ns4/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/fetchlimit/ns3/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/fetchlimit/ns5/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/filters/tests_filter_dns64.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/filters/ns1/unsigned.db up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/filters/ns4/unsigned.db up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/filters/ns5/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/isctest/__init__.py up to 1.1.1.7
	external/mpl/bind/dist/bin/tests/system/isctest/asyncserver.py up to 1.1.1.7
	external/mpl/bind/dist/bin/tests/system/isctest/check.py up to 1.1.1.7
	external/mpl/bind/dist/bin/tests/system/isctest/kasp.py up to 1.1.1.6
	external/mpl/bind/dist/bin/tests/system/isctest/mark.py up to 1.1.1.7
	external/mpl/bind/dist/bin/tests/system/isctest/query.py up to 1.1.1.9
	external/mpl/bind/dist/bin/tests/system/isctest/template.py up to 1.1.1.5
	external/mpl/bind/dist/bin/tests/system/isctest/vars/features.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/ixfr/ans2/ans.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/kasp/setup.sh up to 1.1.1.9
	external/mpl/bind/dist/bin/tests/system/kasp/tests_kasp.py up to 1.1.1.5
	external/mpl/bind/dist/bin/tests/system/ksr/tests_ksr.py up to 1.1.1.6
	external/mpl/bind/dist/bin/tests/system/ksr/ns1/named.conf.j2 up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/ksr/ns1/setup.sh up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/mirror_root_zone/tests_mirror_root_zone.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/nsec/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/nsec3_delegation/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/nsprocessinglimit/ns4/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/nsupdate/setup.sh up to 1.1.1.12
	external/mpl/bind/dist/bin/tests/system/nsupdate/tests.sh up to 1.1.1.18
	external/mpl/bind/dist/bin/tests/system/nsupdate/tests_sh_nsupdate.py up to 1.1.1.6
	external/mpl/bind/dist/bin/tests/system/nsupdate/ns6/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/optout/tests_optout.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/optout/ns2/controls.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/optout/ns2/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/query_source/ns2/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/query_source/ns3/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/query_source/ns4/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/query_source/ns5/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/reclimit/tests.sh up to 1.1.1.10
	external/mpl/bind/dist/bin/tests/system/redirect/setup.sh up to 1.1.1.9
	external/mpl/bind/dist/bin/tests/system/redirect/tests.sh up to 1.1.1.8
	external/mpl/bind/dist/bin/tests/system/redirect/tests_sh_redirect.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/redirect/ns4/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/resolver/tests.sh up to 1.1.1.15
	external/mpl/bind/dist/bin/tests/system/resolver/ns1/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/resolver/ns5/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/resolver/ns7/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/resolver/ns9/root.hint up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover/setup.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/rollover/tests_rollover_manual.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/rollover/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_algo_csk/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_algo_ksk_zsk/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_csk_roll1/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_csk_roll2/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_enable_dnssec/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_going_insecure/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_ksk_3crowd/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_ksk_doubleksk/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_straight2none/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rollover_zsk_prepub/ns3/trusted.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/rpz/testlib/test-data.c up to 1.4
	external/mpl/bind/dist/bin/tests/system/rpzrecurse/ns2/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/serve_stale/tests.sh up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/tests_sh_serve_stale.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns1/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns1/named4.conf.in up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named1.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named2.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named3.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named4.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named5.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named6.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named7.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/serve_stale/ns3/named9.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/statistics/ns3/root.hint up to 1.1.1.4
	external/mpl/bind/dist/bin/tests/system/synthfromdnssec/ns2/root.hints up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/synthfromdnssec/ns3/root.hints up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/synthfromdnssec/ns4/root.hints up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/synthfromdnssec/ns5/root.hints up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/synthfromdnssec/ns6/root.hints up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/unknown/tests.sh up to 1.1.1.8
	external/mpl/bind/dist/bin/tests/system/xfer/tests_retransfer_with_force.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/xfer/tests_xfer.py up to 1.1.1.3
	external/mpl/bind/dist/bin/tests/system/xfer/ns6/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/xfer/ns8/small.db.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/xfer_servers_list/tests_xfer_servers_list.py up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/xferquota/tests_xferquota.py up to 1.1.1.7
	external/mpl/bind/dist/bin/tests/system/xferquota/ns1/named.conf.j2 up to 1.1.1.2
	external/mpl/bind/dist/bin/tests/system/zero/ns3/root.hint up to 1.1.1.3
	external/mpl/bind/dist/bin/tools/nsec3hash.c    up to 1.10
	external/mpl/bind/dist/doc/arm/changelog.rst    up to 1.1.1.8
	external/mpl/bind/dist/doc/arm/conf.py          up to 1.1.1.11
	external/mpl/bind/dist/doc/arm/isc-logo.pdf     up to 1.6
	external/mpl/bind/dist/doc/arm/notes.rst        up to 1.1.1.16
	external/mpl/bind/dist/doc/arm/platforms.inc.rst up to 1.1.1.7
	external/mpl/bind/dist/doc/dnssec-guide/img/remove-ds-2.png up to 1.2
	external/mpl/bind/dist/doc/man/nsupdate.1in     up to 1.1.1.11
	external/mpl/bind/dist/lib/dns/adb.c            up to 1.18
	external/mpl/bind/dist/lib/dns/catz.c           up to 1.18
	external/mpl/bind/dist/lib/dns/db.c             up to 1.15
	external/mpl/bind/dist/lib/dns/diff.c           up to 1.14
	external/mpl/bind/dist/lib/dns/dispatch.c       up to 1.16
	external/mpl/bind/dist/lib/dns/dns64.c          up to 1.9
	external/mpl/bind/dist/lib/dns/dnssec.c         up to 1.20
	external/mpl/bind/dist/lib/dns/dst_api.c        up to 1.19
	external/mpl/bind/dist/lib/dns/gssapictx.c      up to 1.14
	external/mpl/bind/dist/lib/dns/hmac_link.c      up to 1.11
	external/mpl/bind/dist/lib/dns/master.c         up to 1.16
	external/mpl/bind/dist/lib/dns/masterdump.c     up to 1.20
	external/mpl/bind/dist/lib/dns/message.c        up to 1.24
	external/mpl/bind/dist/lib/dns/name.c           up to 1.17
	external/mpl/bind/dist/lib/dns/nta.c            up to 1.15
	external/mpl/bind/dist/lib/dns/opensslrsa_link.c up to 1.14
	external/mpl/bind/dist/lib/dns/qp.c             up to 1.6
	external/mpl/bind/dist/lib/dns/qp_p.h           up to 1.4
	external/mpl/bind/dist/lib/dns/qpcache.c        up to 1.7
	external/mpl/bind/dist/lib/dns/qpzone.c         up to 1.7
	external/mpl/bind/dist/lib/dns/rdataslab.c      up to 1.14
	external/mpl/bind/dist/lib/dns/request.c        up to 1.15
	external/mpl/bind/dist/lib/dns/resolver.c       up to 1.27
	external/mpl/bind/dist/lib/dns/rpz.c            up to 1.19
	external/mpl/bind/dist/lib/dns/rrl.c            up to 1.14
	external/mpl/bind/dist/lib/dns/tkey.c           up to 1.19
	external/mpl/bind/dist/lib/dns/tsig.c           up to 1.16
	external/mpl/bind/dist/lib/dns/validator.c      up to 1.22
	external/mpl/bind/dist/lib/dns/xfrin.c          up to 1.23
	external/mpl/bind/dist/lib/dns/zone.c           up to 1.28
	external/mpl/bind/dist/lib/dns/zoneverify.c     up to 1.14
	external/mpl/bind/dist/lib/dns/include/dns/adb.h up to 1.12
	external/mpl/bind/dist/lib/dns/include/dns/compress.h up to 1.9
	external/mpl/bind/dist/lib/dns/include/dns/db.h up to 1.16
	external/mpl/bind/dist/lib/dns/include/dns/diff.h up to 1.10
	external/mpl/bind/dist/lib/dns/include/dns/dispatch.h up to 1.10
	external/mpl/bind/dist/lib/dns/include/dns/keyvalues.h up to 1.11
	external/mpl/bind/dist/lib/dns/include/dns/nametree.h up to 1.3
	external/mpl/bind/dist/lib/dns/include/dns/nsec.h up to 1.9
	external/mpl/bind/dist/lib/dns/include/dns/qp.h up to 1.5
	external/mpl/bind/dist/lib/dns/include/dns/sdlz.h up to 1.10
	external/mpl/bind/dist/lib/dns/include/dns/ssu.h up to 1.9
	external/mpl/bind/dist/lib/dns/include/dns/stats.h up to 1.10
	external/mpl/bind/dist/lib/dns/include/dns/tsig.h up to 1.11
	external/mpl/bind/dist/lib/dns/include/dns/zone.h up to 1.17
	external/mpl/bind/dist/lib/dns/include/dst/gssapi.h up to 1.10
	external/mpl/bind/dist/lib/dns/rdata/in_1/a_1.c up to 1.13
	external/mpl/bind/dist/lib/isc/histo.c          up to 1.4
	external/mpl/bind/dist/lib/isc/ht.c             up to 1.12
	external/mpl/bind/dist/lib/isc/mem.c            up to 1.20
	external/mpl/bind/dist/lib/isc/picohttpparser.c up to 1.7
	external/mpl/bind/dist/lib/isc/ratelimiter.c    up to 1.11
	external/mpl/bind/dist/lib/isc/result.c         up to 1.16
	external/mpl/bind/dist/lib/isc/tls.c            up to 1.9
	external/mpl/bind/dist/lib/isc/include/isc/hmac.h up to 1.8
	external/mpl/bind/dist/lib/isc/include/isc/result.h up to 1.15
	external/mpl/bind/dist/lib/isc/include/isc/stdio.h up to 1.8
	external/mpl/bind/dist/lib/isc/include/isc/tls.h up to 1.6
	external/mpl/bind/dist/lib/isc/netmgr/http.c    up to 1.9
	external/mpl/bind/dist/lib/isc/netmgr/tcp.c     up to 1.15
	external/mpl/bind/dist/lib/isccfg/check.c       up to 1.7
	external/mpl/bind/dist/lib/isccfg/include/isccfg/aclconf.h up to 1.10
	external/mpl/bind/dist/lib/ns/client.c          up to 1.29
	external/mpl/bind/dist/lib/ns/query.c           up to 1.29
	external/mpl/bind/dist/lib/ns/update.c          up to 1.21
	external/mpl/bind/dist/lib/ns/xfrout.c          up to 1.18
	external/mpl/bind/dist/tests/dns/dispatch_test.c up to 1.5
	external/mpl/bind/dist/tests/dns/dnstap_test.c  up to 1.5
	external/mpl/bind/dist/tests/dns/qpdb_test.c    up to 1.4
	external/mpl/bind/dist/tests/dns/rsa_test.c     up to 1.4
	external/mpl/bind/dist/tests/dns/tsig_test.c    up to 1.8
	external/mpl/bind/dist/tests/dns/update_test.c  up to 1.5
	external/mpl/bind/dist/tests/isc/mem_test.c     up to 1.6
	external/mpl/bind/dist/tests/isc/time_test.c    up to 1.4
	external/mpl/bind/include/config.h              up to 1.28
	external/mpl/bind/lib/libdns/dns.common.expsym  up to 1.9
	external/mpl/bind/lib/libdns/shlib_version      up to 1.21
	distrib/sets/lists/base/shl.mi			(manually edited)
	distrib/sets/lists/debug/shl.mi			(manually edited)
	doc/3RDPARTY					(manually edited)

Import bind 9.20.24/MPL
@
text
@a0 12
options {
	directory ".";
};

view chaos ch {
        match-clients { any; };
        recursion yes;
        zone "." {
                type hint;
                file "chaos.hints";
        };
};
@


