| Message ID | 20261009221321.1995938-1-matthias.fischer@ipfire.org |
|---|---|
| State | New |
| Headers |
Return-Path: <development+bounces-2792-patchwork=ipfire.org@lists.ipfire.org> Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR1" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4j1h2r2Zj5z3wqm for <patchwork@web04.haj.ipfire.org>; Fri, 09 Oct 2026 22:13:40 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE2" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4j1h2q6LqQz7cN for <patchwork@ipfire.org>; Fri, 09 Oct 2026 22:13:39 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4j1h2q5Xmrz2xXH for <patchwork@ipfire.org>; Fri, 09 Oct 2026 22:13:39 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR1" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4j1h2n11mwz2xHd for <development@lists.ipfire.org>; Fri, 09 Oct 2026 22:13:37 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4j1h2f43vnz3GM; Fri, 09 Oct 2026 22:13:30 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1791584010; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=FhZO6fXx3j5Zg/YhE7steAEWEit2IpoUQT/4TOb9WzU=; b=RI4w0l/5c54rSnzw0vAGGyovGkriGXCPq0V2It5JbhWriS92jcV+ojW3ePEED3k7ym0n3V 3kE1izpqOP+K4+Dw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1791584010; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=FhZO6fXx3j5Zg/YhE7steAEWEit2IpoUQT/4TOb9WzU=; b=sBC1vEjHInXjQ420WPX4tYF2+Mfo/5saY46/5WMen95UpWsEpUpammTGF4l9c1XAlVYxbo cHUc9X7cZV7nShSl23J/6yPGG9f5DoUWEqbZeNqCQRYdCRDUtpOe9McJzz55pcPAOjFn1I LwME0l2BsAZZ2ZFSs2cyrPjmU99OTmpTJx2DA0FPCr6mKYh8b0oPYFDmPR3R38uGhX+Hk0 rkEG1euMNf2bFH/d7B/24FaEyligQf6FmGo4TdUH8e5rjktHW6EnNkAHOrgNUMTFJ45gc8 Z1CeYXrsbg4iziTmQiJOB9vOn/ZJNH5CG0l51e+3+4WrQtASd+/kpc7+EP9qLg== From: Matthias Fischer <matthias.fischer@ipfire.org> To: development@lists.ipfire.org Cc: Matthias Fischer <matthias.fischer@ipfire.org> Subject: [PATCH] knot: Update to 3.6.1 Date: Sat, 10 Oct 2026 00:13:18 +0200 Message-ID: <20261009221321.1995938-1-matthias.fischer@ipfire.org> Precedence: list List-Id: <development.lists.ipfire.org> List-Subscribe: <https://lists.ipfire.org/>, <mailto:development+subscribe@lists.ipfire.org?subject=subscribe> List-Unsubscribe: <https://lists.ipfire.org/>, <mailto:development+unsubscribe@lists.ipfire.org?subject=unsubscribe> List-Post: <mailto:development@lists.ipfire.org> List-Help: <mailto:development+help@lists.ipfire.org?subject=help> Sender: <development@lists.ipfire.org> Mail-Followup-To: <development@lists.ipfire.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit |
| Series |
knot: Update to 3.6.1
|
|
Commit Message
Matthias Fischer
9 Oct 2026, 10:13 p.m. UTC
For details see:
https://www.knot-dns.cz/2026-10-09-version-361.html
"Version 3.6.1
Friday, October 9, 2026
Features:
mod-ecs: new module for setting the ECS scope prefix length (Thanks to Branko Mijuskovic)
Improvements:
knotd: additional SOA consistency checks when processing incoming XFR
knotd: DDNS over 0-RTT QUIC/TLS is forbidden
knotd: new warning if difference(-no-serial) is enabled on a secondary zone
knotc: control blocking timeout is per full command, not per each zone
kdig: backward compatibility for +noidn as an alias for +noidnout
libknot: extra checks for malformed IPv4 and TCP packets in XDP filter (Thanks to Joshua Rogers)
src,tests: various compatibility fixes for SmartOS #980
doc: various improvements
Bugfixes:
knotd: missing synchronization between catalog reload and worker suspension
knotd: race condition between pausing/resuming events, zonedb update, and reload/conf-commit
knotd: non-consumed DoT 0-RTT early data can cause memory exhaustion (Thanks to Yuxiao Wu)
knotd: server can crash if NSEC3-enabled zone has empty NSEC3 chain (Thanks to Yuxiao Wu)
knotd: server sends 3 session tickets over DoQ
knotd: missing checks for malformed sentinel-related replies from Redis (Thanks to Joshua Rogers)
knotd: defective error handling during zone update (Thanks to Joshua Rogers)
knotd: defective TSIG MAC truncation processing (Thanks to Joshua Rogers)
knotd: zone update commit reads parent zone contents without RCU protection (Thanks to Joshua Rogers)
knotd: parent-check TTL can overflow KSK retirement delay (Thanks to Joshua Rogers)
knotd: missing DDNS queue synchronization during reload (Thanks to Joshua Rogers)
keymgr: validate-skr returns success for cryptographically invalid SKR signatures (Thanks to Joshua Rogers)
kdig: missing check for malformed EDNS/REPORTCHANNEL data (Thanks to Joshua Rogers)
libknot: defective output buffer handling in TCP over XDP
libknot: auto-generated TLS key file follows symlinks (Thanks to Joshua Rogers)
libknot: missing checks for malformed data in rrset-dump (Thanks to Joshua Rogers)
libzsanner: possible out-of-bounds write when parsing DELEG/DELEGPARAM dname (Thanks to Joshua Rogers)
redis: possible use-after-free when rrset index update fails (Thanks to Joshua Rogers)
redis: incorrect arity check for KNOT_BIN.UPD.LOAD (Thanks to Joshua Rogers)
redis: KNOT.ZONE.INFO crashes on nonexistent zone (Thanks to Joshua Rogers)
redis: update commit uses freed zset element buffer while applying updates (Thanks to Joshua Rogers)
python: receive_block() doesn't return data from the 'status' command"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
---
lfs/knot | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lfs/knot b/lfs/knot index 97995b669..61f9ee0d9 100644 --- a/lfs/knot +++ b/lfs/knot @@ -24,7 +24,7 @@ include Config -VER = 3.6.0 +VER = 3.6.1 THISAPP = knot-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 454d12deb35c91fd3c3e71cfd4021bd0d36fb39446e3cef41a47df3bbc0362950de1a21eb742d936dbce13a822891b313da335b8bb21026b88d4d985d8c763c0 +$(DL_FILE)_BLAKE2 = b052613f66af93ca041d77d73876361b980bb22f929a6330da38d5de213c29833ee875c1fcce89bef4047f55936fd743b302b3fee53f7b21cce60a2c219e8601 install : $(TARGET)