Commit Graph

6249 Commits

Author SHA1 Message Date
DL6ER 231a9853bd If dns.domainNeeded is set, refuse to send plain domain queries (like laptop) upstream at all.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-03-07 16:58:52 +01:00
DL6ER ad46a1018a We should only set local=/<domain>/ if there is no conditional forwarding setting (v6 supports multiple reverse lookup servers), otherwise, this creates a harmless but nonetheless needlessly confusing configuration.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-03-07 16:55:11 +01:00
Dominik 93d01d9c5d Merge pull request #1891 from pi-hole/fix/migration_message
Improve config migration logging
2024-03-04 19:41:57 +01:00
Dominik 4b2a4be94c Merge pull request #1868 from pi-hole/new/useWAL
Make WAL mode for pihole-FTL.db optional
2024-03-04 19:40:29 +01:00
Dominik 7ef8e6c916 Merge pull request #1882 from pi-hole/merge-v5-6
Sync v5 -> v6
2024-03-02 18:30:31 +01:00
Dominik d4792bb70c Merge pull request #1886 from pi-hole/tweak/allow_adlist_dups
Allow adlist duplicates
2024-03-02 18:28:41 +01:00
yubiuser 661d9e3be0 Merge pull request #1897 from pi-hole/dependabot-github_actions-development-v6-github_action-dependencies-b4913446bb
Bump the github_action-dependencies group with 3 updates
2024-03-02 12:49:10 +01:00
dependabot[bot] a1d6f85bf1 Bump the github_action-dependencies group with 3 updates
Bumps the github_action-dependencies group with 3 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action), [Wandalen/wretry.action](https://github.com/wandalen/wretry.action) and [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `docker/setup-buildx-action` from 3.0.0 to 3.1.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/v3.0.0...v3.1.0)

Updates `Wandalen/wretry.action` from 1.4.4 to 1.4.5
- [Release notes](https://github.com/wandalen/wretry.action/releases)
- [Commits](https://github.com/wandalen/wretry.action/compare/v1.4.4...v1.4.5)

Updates `actions/download-artifact` from 4.1.2 to 4.1.4
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/v4.1.2...v4.1.4)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github_action-dependencies
- dependency-name: Wandalen/wretry.action
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github_action-dependencies
- dependency-name: actions/download-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github_action-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-03-02 10:26:16 +00:00
Dominik bffd2bd4ba Merge pull request #1892 from pi-hole/fix/dnsmasq_resource_warning
Fix spurious "resource limit exceeded" messages
2024-02-20 05:27:37 +01:00
DL6ER cf06e53872 Update embedded dnsmasq version to 2.90+1
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-19 13:59:52 +01:00
Simon Kelley 157b589391 Fix spurious "resource limit exceeded" messages.
Replies from upstream with a REFUSED rcode can result in
log messages stating that a resource limit has been exceeded,
which is not the case.

Thanks to Dominik Derigs and the Pi-hole project for
spotting this.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-19 13:59:52 +01:00
DL6ER d5cf5799c1 Merge branch 'development' into merge-v5-6
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-17 16:43:15 +01:00
DL6ER d74d2a1e1c Improve config migration logging
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-17 16:27:40 +01:00
DL6ER 750db7ecda Merge branch 'development-v6' into tweak/allow_adlist_dups
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 21:06:43 +01:00
Dominik 41725fd343 Merge pull request #1887 from pi-hole/tweak/apppw_descrition
Improve description of GET /auth/app endpoint
2024-02-13 21:05:42 +01:00
Dominik 6681804b3c Merge pull request #1875 from pi-hole/update/dnsmasq
Update embedded dnsmasq to v2.90
2024-02-13 20:21:55 +01:00
Dominik 2582043a2d Apply code review
Co-authored-by: RD WebDesign <github@rdwebdesign.com.br>
Signed-off-by: Dominik <DL6ER@users.noreply.github.com>
2024-02-13 19:58:27 +01:00
DL6ER a326d80869 Update dnsmasq version to 2.90
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 17:10:05 +01:00
DL6ER 2c7c19c1ae Update expected dnsmasq warnings
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 17:07:17 +01:00
DL6ER 96f4acb516 Add documentation for automatically added new DNSSEC-related metrics
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 17:03:05 +01:00
Simon Kelley c95816f3b9 Reverse suppression of ANY query answer logging.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:46:14 +01:00
Simon Kelley 4b351cbe36 Add --dnssec-limits option.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:45:54 +01:00
Simon Kelley cb577f318e Better allocation code for DS digest cache.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:45:19 +01:00
Simon Kelley dcd12a2be6 Better stats and logging from DNSSEC resource limiting.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:45:12 +01:00
Simon Kelley 84161ed295 Overhaul data checking in NSEC code.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:44:06 +01:00
Simon Kelley 1dbbdc96ca Rework validate-by-DS to avoid DoS vuln without arbitrary limits.
By calculating the hash of a DNSKEY once for each digest algo,
we reduce the hashing work from (no. DS) x (no. DNSKEY) to
(no. DNSKEY) x (no. distinct digests)

The number of distinct digests can never be more than 255 and
it's limited by which hashes we implement, so currently only 4.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:43:59 +01:00
Simon Kelley b5e7dd448b Update EDE code -> text conversion.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:43:11 +01:00
Simon Kelley f141efdeba Parameterise work limits for DNSSEC validation.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:43:03 +01:00
Simon Kelley d92159a836 Fix error introduced in 635bc51cac3d5d7dd49ce9e27149cf7e402b7e79
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:40:32 +01:00
Simon Kelley 0b9e5543d2 Measure cryptographic work done by DNSSEC.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:40:27 +01:00
Simon Kelley ddf44bf916 Update NSEC3 iterations handling to conform with RFC 9276.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:38:55 +01:00
Simon Kelley aa565b1dff Update header with new EDE values.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:38:50 +01:00
Simon Kelley ebbfb893bd Protection against pathalogical DNSSEC domains.
An attacker can create DNSSEC signed domains which need a lot of
work to verfify. We limit the number of crypto operations to
avoid DoS attacks by CPU exhaustion.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 16:38:46 +01:00
DL6ER 81a1da69cb Improve description of GET /auth/app endpoint
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 14:52:33 +01:00
DL6ER 8325db3cc8 Set REPLY of queries that failed DNSSEC validation to NONE (if not already set elsehow)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 14:28:47 +01:00
DL6ER fbd7aa7761 Check for UNKNOWN status and replies during CI testing
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 10:38:30 +01:00
DL6ER 8b3c39015d Add RFC 8482 filtering (Providing Minimal-Sized Responses to DNS Queries That Have QTYPE=ANY) by default
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 09:51:53 +01:00
DL6ER 7a919cbf59 Allow narrowing down the (ad)list type using the (optional) query parameter ?type={allow,block}
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 08:42:08 +01:00
DL6ER f6fb93e997 Update embedded dnsmasq version to 2.90test4
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 07:19:15 +01:00
Simon Kelley 75648b4def Make --filter-rr=ANY filter the answer to ANY queries.
Thanks to Dominik Derigs for an earlier patch which inspired this.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 07:15:03 +01:00
Simon Kelley 8cdead96a5 Tweak logging and special handling of T_ANY in rr-filter code.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-13 07:12:25 +01:00
DL6ER e3e839880e Merge branch 'development-v6' into update/dnsmasq 2024-02-13 07:12:16 +01:00
Dominik 9e3ccd917d Merge pull request #1797 from pi-hole/new/multi_revServer
Add support for multiple reverse servers
2024-02-11 06:52:31 +01:00
Dominik 54262aeba2 Merge pull request #1878 from pi-hole/fix/debug_api_description
Fix debug.api config options description.
2024-02-10 20:56:25 +01:00
Dominik 5940c62763 Merge pull request #1719 from pi-hole/tweak/env_vars_list
Check all env vars and suggest alternatives for misspelled keys
2024-02-10 16:21:42 +01:00
yubiuser c994dad4f5 Merge pull request #1880 from pi-hole/dependabot-github_actions-development-v6-github_action-dependencies-d9773afac8
Bump the github_action-dependencies group with 3 updates
2024-02-10 12:36:38 +01:00
dependabot[bot] c2f690b3ab Bump the github_action-dependencies group with 3 updates
Bumps the github_action-dependencies group with 3 updates: [Wandalen/wretry.action](https://github.com/wandalen/wretry.action), [actions/upload-artifact](https://github.com/actions/upload-artifact) and [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `Wandalen/wretry.action` from 1.3.0 to 1.4.4
- [Release notes](https://github.com/wandalen/wretry.action/releases)
- [Commits](https://github.com/wandalen/wretry.action/compare/v1.3.0...v1.4.4)

Updates `actions/upload-artifact` from 4.3.0 to 4.3.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v4.3.0...v4.3.1)

Updates `actions/download-artifact` from 4.1.1 to 4.1.2
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/v4.1.1...v4.1.2)

---
updated-dependencies:
- dependency-name: Wandalen/wretry.action
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github_action-dependencies
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github_action-dependencies
- dependency-name: actions/download-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github_action-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-02-10 11:00:33 +00:00
DL6ER ec37efd77f Fix debug.api config options description.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-10 09:34:25 +01:00
Dominik 82f8abe71f Merge pull request #1877 from pi-hole/tweak/dnssec_default
DNSSEC validation should not be enabled by default in v6
2024-02-09 22:45:57 +01:00
DL6ER 16cc1027fb DNSSEC validation should not be enabled by default - it wasn't in v5, either. The reason for this is that it may be causing issues on devices with broken/missing RTCs where NTP time synchronization relies on DNS resolution
Signed-off-by: DL6ER <dl6er@dl6er.de>
2024-02-09 21:51:31 +01:00