Revisions of dnsmasq

Marcus Meissner's avatar Marcus Meissner (msmeissn) accepted request 981335 from Callum Farmer's avatar Callum Farmer (gmbr3) (revision 147)
- Move the dbus-1 system.d file to /usr (bsc#1200344)
buildservice-autocommit accepted request 969348 from Factory Maintainer's avatar Factory Maintainer (factory-maintainer) (revision 146)
baserev update by copy to link target
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 145)
- bsc#1197872, CVE-2022-0934, dnsmasq-CVE-2022-0934.patch:
  Heap use after free in dhcp6_no_relay
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 144)
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 143)
- bsc#1192529, dnsmasq-resolv-conf.patch:
  Fix a segfault when re-reading an empty resolv.conf
- Remove "nogroup" membership from the dnsmasq user.
Reinhard Max's avatar Reinhard Max (rmax) accepted request 928184 from Callum Farmer's avatar Callum Farmer (gmbr3) (revision 142)
- Use systemd-sysusers from 15.3 onwards
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 141)
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 140)
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 139)
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 138)
- SLE bugs that got fixed upstream between 2.79 and 2.86, but for
  which we need to keep references when syncing Factory to SLE:
  * bsc#1176076: dnsmasq-servfail.patch
  * bsc#1156543: dnsmasq-siocgstamp.patch
  * bsc#1138743: dnsmasq-cache-size.patch
  * bsc#1076958: CVE-2017-15107, dnsmasq-CVE-2017-15107.patch
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 137)
- Update to 2.86:
  * Handle DHCPREBIND requests in the DHCPv6 server code.
  * Fix bug which caused dnsmasq to lose track of processes forked
    to handle TCP DNS connections under heavy load.
  * Major rewrite of the DNS server and domain handling code. This
    should be largely transparent, but it drastically improves
    performance and reduces memory foot-print when configuring
    large numbers of domains.
  * Revise resource handling for number of concurrent DNS queries.
  * Improve efficiency of DNSSEC.
  * Connection track mark based DNS query filtering.
  * Allow smaller than 64 prefix lengths in synth-domain, with
    caveats.
    --synth-domain=1234:4567::/56,example.com is now valid.
  * Make domains generated by --synth-domain appear in replies
    when in authoritative mode.
  * Ensure CAP_NET_ADMIN capability is available when conntrack
    is configured.
  * When --dhcp-hostsfile --dhcp-optsfile and --addn-hosts are
    given a directory as argument, define the order in which files
    within that directory are read (alphabetical order of filename).
- Added hardening to systemd service(s) (bsc#1181400).
Reinhard Max's avatar Reinhard Max (rmax) accepted request 918936 from Johannes Segitz's avatar Johannes Segitz (jsegitz) (revision 136)
Automatic systemd hardening effort by the security team. This has not been tested. For details please see https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort
Reinhard Max's avatar Reinhard Max (rmax) accepted request 899810 from Callum Farmer's avatar Callum Farmer (gmbr3) (revision 135)
- Add now working CONFIG parameter to sysusers generator
Reinhard Max's avatar Reinhard Max (rmax) accepted request 896893 from Callum Farmer's avatar Callum Farmer (gmbr3) (revision 134)
- Change to using systemd-sysusers on TW
buildservice-autocommit accepted request 888631 from Factory Maintainer's avatar Factory Maintainer (factory-maintainer) (revision 133)
baserev update by copy to link target
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 132)
- Update to 2.85:
  * Fix problem with DNS retries in 2.83/2.84.
  * Tweak sort order of tags in get-version.
  * Avoid treating a --dhcp-host which has an IPv6 address as
    eligible for use with DHCPv4 on the grounds that it has
    no address, and vice-versa.
  * Add --dynamic-host option: A and AAAA records which take their
    network part from the network of a local interface. Useful
    for routers with dynamically prefixes.
  * Teach --bogus-nxdomain and --ignore-address to take an IPv4
    subnet.
  * CVE-2021-3448, bsc#1183709: Use random source ports where
    possible if source addresses/interfaces in use.
  * Change the method of allocation of random source ports for DNS.
  * Scale the size of the DNS random-port pool based on the
    value of the --dns-forward-max configuration.
  * Tweak TFTP code to check sender of all received packets, as
    specified in RFC 1350 para 4.
Reinhard Max's avatar Reinhard Max (rmax) committed (revision 131)
Fix URLs.
Reinhard Max's avatar Reinhard Max (rmax) accepted request 870366 from Dirk Mueller's avatar Dirk Mueller (dirkmueller) (revision 130)
- update to 2.84:
  * Change HAVE_NETTLEHASH compile-time to HAVE_CRYPTOHASH
  * Tidy initialisation in hash_questions.c
  * Optimise sort_rrset for the case where the RR type
  * Move fd into frec_src
buildservice-autocommit accepted request 867893 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 129)
baserev update by copy to link target
Marcus Meissner's avatar Marcus Meissner (msmeissn) accepted request 867249 from Callum Farmer's avatar Callum Farmer (gmbr3) (revision 128)
- Fix building with lua54
Displaying revisions 21 - 40 of 167
openSUSE Build Service is sponsored by