From patchwork Fri Oct 9 22:13:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Matthias Fischer X-Patchwork-Id: 10373 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR1" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4j1h2r2Zj5z3wqm for ; Fri, 09 Oct 2026 22:13:40 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE2" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4j1h2q6LqQz7cN for ; Fri, 09 Oct 2026 22:13:39 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4j1h2q5Xmrz2xXH for ; Fri, 09 Oct 2026 22:13:39 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR1" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4j1h2n11mwz2xHd for ; Fri, 09 Oct 2026 22:13:37 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4j1h2f43vnz3GM; Fri, 09 Oct 2026 22:13:30 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1791584010; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=FhZO6fXx3j5Zg/YhE7steAEWEit2IpoUQT/4TOb9WzU=; b=RI4w0l/5c54rSnzw0vAGGyovGkriGXCPq0V2It5JbhWriS92jcV+ojW3ePEED3k7ym0n3V 3kE1izpqOP+K4+Dw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1791584010; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=FhZO6fXx3j5Zg/YhE7steAEWEit2IpoUQT/4TOb9WzU=; b=sBC1vEjHInXjQ420WPX4tYF2+Mfo/5saY46/5WMen95UpWsEpUpammTGF4l9c1XAlVYxbo cHUc9X7cZV7nShSl23J/6yPGG9f5DoUWEqbZeNqCQRYdCRDUtpOe9McJzz55pcPAOjFn1I LwME0l2BsAZZ2ZFSs2cyrPjmU99OTmpTJx2DA0FPCr6mKYh8b0oPYFDmPR3R38uGhX+Hk0 rkEG1euMNf2bFH/d7B/24FaEyligQf6FmGo4TdUH8e5rjktHW6EnNkAHOrgNUMTFJ45gc8 Z1CeYXrsbg4iziTmQiJOB9vOn/ZJNH5CG0l51e+3+4WrQtASd+/kpc7+EP9qLg== From: Matthias Fischer To: development@lists.ipfire.org Cc: Matthias Fischer Subject: [PATCH] knot: Update to 3.6.1 Date: Sat, 10 Oct 2026 00:13:18 +0200 Message-ID: <20261009221321.1995938-1-matthias.fischer@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 For details see: https://www.knot-dns.cz/2026-10-09-version-361.html "Version 3.6.1 Friday, October 9, 2026 Features: mod-ecs: new module for setting the ECS scope prefix length (Thanks to Branko Mijuskovic) Improvements: knotd: additional SOA consistency checks when processing incoming XFR knotd: DDNS over 0-RTT QUIC/TLS is forbidden knotd: new warning if difference(-no-serial) is enabled on a secondary zone knotc: control blocking timeout is per full command, not per each zone kdig: backward compatibility for +noidn as an alias for +noidnout libknot: extra checks for malformed IPv4 and TCP packets in XDP filter (Thanks to Joshua Rogers) src,tests: various compatibility fixes for SmartOS #980 doc: various improvements Bugfixes: knotd: missing synchronization between catalog reload and worker suspension knotd: race condition between pausing/resuming events, zonedb update, and reload/conf-commit knotd: non-consumed DoT 0-RTT early data can cause memory exhaustion (Thanks to Yuxiao Wu) knotd: server can crash if NSEC3-enabled zone has empty NSEC3 chain (Thanks to Yuxiao Wu) knotd: server sends 3 session tickets over DoQ knotd: missing checks for malformed sentinel-related replies from Redis (Thanks to Joshua Rogers) knotd: defective error handling during zone update (Thanks to Joshua Rogers) knotd: defective TSIG MAC truncation processing (Thanks to Joshua Rogers) knotd: zone update commit reads parent zone contents without RCU protection (Thanks to Joshua Rogers) knotd: parent-check TTL can overflow KSK retirement delay (Thanks to Joshua Rogers) knotd: missing DDNS queue synchronization during reload (Thanks to Joshua Rogers) keymgr: validate-skr returns success for cryptographically invalid SKR signatures (Thanks to Joshua Rogers) kdig: missing check for malformed EDNS/REPORTCHANNEL data (Thanks to Joshua Rogers) libknot: defective output buffer handling in TCP over XDP libknot: auto-generated TLS key file follows symlinks (Thanks to Joshua Rogers) libknot: missing checks for malformed data in rrset-dump (Thanks to Joshua Rogers) libzsanner: possible out-of-bounds write when parsing DELEG/DELEGPARAM dname (Thanks to Joshua Rogers) redis: possible use-after-free when rrset index update fails (Thanks to Joshua Rogers) redis: incorrect arity check for KNOT_BIN.UPD.LOAD (Thanks to Joshua Rogers) redis: KNOT.ZONE.INFO crashes on nonexistent zone (Thanks to Joshua Rogers) redis: update commit uses freed zset element buffer while applying updates (Thanks to Joshua Rogers) python: receive_block() doesn't return data from the 'status' command" Signed-off-by: Matthias Fischer --- lfs/knot | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lfs/knot b/lfs/knot index 97995b669..61f9ee0d9 100644 --- a/lfs/knot +++ b/lfs/knot @@ -24,7 +24,7 @@ include Config -VER = 3.6.0 +VER = 3.6.1 THISAPP = knot-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 454d12deb35c91fd3c3e71cfd4021bd0d36fb39446e3cef41a47df3bbc0362950de1a21eb742d936dbce13a822891b313da335b8bb21026b88d4d985d8c763c0 +$(DL_FILE)_BLAKE2 = b052613f66af93ca041d77d73876361b980bb22f929a6330da38d5de213c29833ee875c1fcce89bef4047f55936fd743b302b3fee53f7b21cce60a2c219e8601 install : $(TARGET)