From patchwork Wed Sep 9 11:32:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Matthias Fischer X-Patchwork-Id: 10183 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hfzFc13zNz3wqG for ; Wed, 09 Sep 2026 11:33:08 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hfzFb3ZSVz6HG for ; Wed, 09 Sep 2026 11:33:07 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hfzFb2qFpz2yq0 for ; Wed, 09 Sep 2026 11:33:07 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hfzFX5VXGz2xPP for ; Wed, 09 Sep 2026 11:33:04 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hfzFW4Ns3zvw; Wed, 09 Sep 2026 11:33:03 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1788953583; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=xbkR5F1afn7+8xCPEifzkUTATRSVYZ7FYIKMr57ggME=; b=x33Nshp3HBQswnsFeyi+xoNbvOkH0p3UKFWyYBxsgJJXqgujXT9pzbkZF6dPTYRi0FbgUB bNMGrLFEWy5UjnCg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1788953583; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=xbkR5F1afn7+8xCPEifzkUTATRSVYZ7FYIKMr57ggME=; b=acJpuvqOKc0Kq5jg6t0B2POPmBDpryy4+1bcy5xbk1v5BaWCY7WJnUTU5/XFpHO8WizlYY sPllwnHELegCqgMwhcKCJrRkS6BX9BK+3unNB6MAM6jTBJhmbIevuft+YgrehD+LZstkHd nPP1n0e/aPKFdqtd3cAr4DzHlIlzT/EzRIyK4hrRhvUcBhLE472seoRXOpStVC4uY2TzvG 9FeK+E2ZhmK0nEPtrvbSBl0O7KHcIOvw3bjKGEkUEkb9HO6mmzkCyf0UmReJViiXKEdlWh MSsUNRlh4G3AbLUyIQsDPvhzztZGRcLz/ladvruj3sJ1iKXKxPGs4DpO296BiA== From: Matthias Fischer To: development@lists.ipfire.org Cc: Matthias Fischer Subject: [PATCH] knot: Update to 3.6.0 Date: Wed, 9 Sep 2026 13:32:45 +0200 Message-ID: <20260909113255.3405102-1-matthias.fischer@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 For details see: https://www.knot-dns.cz/2026-09-08-version-360.html "Version 3.6.0 Tuesday, September 8, 2026 Features: knotd: DELEG-aware answering (see 'zone.deleg-aware') knotd: DELEG-aware zone signing (see 'policy.deleg-adt') knotd: configurable storage for the last signed serial (see 'zone.dnssec-metadata-db') knotd: optional jitter for DNSSEC events (see 'policy.dnssec-jitter') knotd: optional jitter for SOA refresh events (see 'zone.refresh-jitter') knotd: implemented a "trash bin" for deleted DNSSEC keys (see 'DNSSEC key delete and recovery') knotc: zone retransfer with automatic IXFR fix-up (see '+fixfr') kdig: per zone DNSSEC answer validation (see '+validate') utils: automatic LMDB migration from version 0.9 using embedded LMDB 0.9.35 libknot: support for DELEG and DELEGPARAM record types Improvements: knotd: millisecond-precision prefix timestamps in non-syslog logging knotd: enforced serial policy during initial zone file load if 'difference-no-serial' is enabled knotd: if NXDOMAIN answering encounters a failure, SERVFAIL is returned knotd: new check for mismatches between zone and parent NS RRsets knotd: the control timeout applies to blocking events knotc: better compatibility with SmartOS #979 kdig: extended IDN transformation configuration (see '+[no]idnin' and '+[no]idnout') keymgr: optional digest algorithm option for 'ds' command doc: described cleanup of legacy DNSSEC keys (see 'Cleanup of removed legacy DNSSEC keys') doc: described the zone deconfiguration procedure (see 'Zone removal') doc: various improvements Bugfixes: knotd: CNAME leading to a different zone is followed mod-onlinesign: inconsistent SOA TTL in negative responses Packaging: distro: Debian 11 and Ubuntu 20.04 no longer supported debian,ubuntu: i386 and armhf architectures no longer supported Compatibility: knotd: default value for 'policy.rrsig-pre-refresh' changed to 0.005 * 'policy.rrsig-lifetime' knotd: removed TCP Fast Open support ('server.tcp-fastopen' has no effect) knotd: default storage for the last signed serial is KASP database again knotd: zone file load with 'difference' no longer tolerates zone changes without incremented SOA serial knotd: added colon to TZ specification in non-system logging according to ISO 8601 knotd: the maximum allowed number of NSEC3 iterations is restricted to 256 knotd: changing NSEC3PARAM via DDNS is no longer possible knotc: unified and extended some command output kdig: removed '+noidn' in favor of '+[no]idnin' and '+[no]idnout' kdig: removed TCP Fast Open support ('+fastopen') mod-dnsproxy: removed TCP Fast Open support ('tcp-fastopen') libs: libdnssec integrated into libknot libs: minimum required version of GnuTLS is 3.6.12 libs: added a workaround for compatibility with LMDB mdb-drop() version 1.0.0 tests-fuzz: removed AFL support" Signed-off-by: Matthias Fischer --- config/rootfiles/common/knot | 38 ++++++++++++++---------------------- lfs/knot | 4 ++-- 2 files changed, 17 insertions(+), 25 deletions(-) diff --git a/config/rootfiles/common/knot b/config/rootfiles/common/knot index cde89bede..20bad49a3 100644 --- a/config/rootfiles/common/knot +++ b/config/rootfiles/common/knot @@ -4,22 +4,6 @@ usr/bin/knsec3hash usr/bin/knsupdate #usr/include/knot #usr/include/knot/module.h -#usr/include/libdnssec -#usr/include/libdnssec/binary.h -#usr/include/libdnssec/crypto.h -#usr/include/libdnssec/digest.h -#usr/include/libdnssec/dnssec.h -#usr/include/libdnssec/error.h -#usr/include/libdnssec/key.h -#usr/include/libdnssec/keyid.h -#usr/include/libdnssec/keystore.h -#usr/include/libdnssec/keytag.h -#usr/include/libdnssec/nsec.h -#usr/include/libdnssec/pem.h -#usr/include/libdnssec/random.h -#usr/include/libdnssec/sign.h -#usr/include/libdnssec/tsig.h -#usr/include/libdnssec/version.h #usr/include/libknot #usr/include/libknot/attribute.h #usr/include/libknot/codes.h @@ -33,6 +17,19 @@ usr/bin/knsupdate #usr/include/libknot/db/db_trie.h #usr/include/libknot/descriptor.h #usr/include/libknot/dname.h +#usr/include/libknot/dnssec +#usr/include/libknot/dnssec/binary.h +#usr/include/libknot/dnssec/crypto.h +#usr/include/libknot/dnssec/digest.h +#usr/include/libknot/dnssec/key.h +#usr/include/libknot/dnssec/keyid.h +#usr/include/libknot/dnssec/keystore.h +#usr/include/libknot/dnssec/keytag.h +#usr/include/libknot/dnssec/nsec.h +#usr/include/libknot/dnssec/pem.h +#usr/include/libknot/dnssec/random.h +#usr/include/libknot/dnssec/sign.h +#usr/include/libknot/dnssec/tsig.h #usr/include/libknot/dynarray.h #usr/include/libknot/endian.h #usr/include/libknot/errcode.h @@ -85,18 +82,13 @@ usr/bin/knsupdate #usr/include/libzscanner/error.h #usr/include/libzscanner/scanner.h #usr/include/libzscanner/version.h -#usr/lib/libdnssec.la -#usr/lib/libdnssec.so -usr/lib/libdnssec.so.10 -usr/lib/libdnssec.so.10.0.0 #usr/lib/libknot.la #usr/lib/libknot.so -usr/lib/libknot.so.16 -usr/lib/libknot.so.16.0.0 +usr/lib/libknot.so.17 +usr/lib/libknot.so.17.0.0 #usr/lib/libzscanner.la #usr/lib/libzscanner.so usr/lib/libzscanner.so.5 usr/lib/libzscanner.so.5.0.0 -#usr/lib/pkgconfig/libdnssec.pc #usr/lib/pkgconfig/libknot.pc #usr/lib/pkgconfig/libzscanner.pc diff --git a/lfs/knot b/lfs/knot index c3626cad7..97995b669 100644 --- a/lfs/knot +++ b/lfs/knot @@ -24,7 +24,7 @@ include Config -VER = 3.5.8 +VER = 3.6.0 THISAPP = knot-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = e7793b469c7782a3aa14c8e02fb038d8d1d943283a9cd4dde7bee6a7296d5c4149e0752f8741317dabadbe4dfe930c715a8c82b6c27bb483b8f358c17acac3c4 +$(DL_FILE)_BLAKE2 = 454d12deb35c91fd3c3e71cfd4021bd0d36fb39446e3cef41a47df3bbc0362950de1a21eb742d936dbce13a822891b313da335b8bb21026b88d4d985d8c763c0 install : $(TARGET)