DL6ER
231a9853bd
If dns.domainNeeded is set, refuse to send plain domain queries (like laptop) upstream at all.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-03-07 16:58:52 +01:00
DL6ER
ad46a1018a
We should only set local=/<domain>/ if there is no conditional forwarding setting (v6 supports multiple reverse lookup servers), otherwise, this creates a harmless but nonetheless needlessly confusing configuration.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-03-07 16:55:11 +01:00
Dominik
93d01d9c5d
Merge pull request #1891 from pi-hole/fix/migration_message
...
Improve config migration logging
2024-03-04 19:41:57 +01:00
Dominik
4b2a4be94c
Merge pull request #1868 from pi-hole/new/useWAL
...
Make WAL mode for pihole-FTL.db optional
2024-03-04 19:40:29 +01:00
Dominik
7ef8e6c916
Merge pull request #1882 from pi-hole/merge-v5-6
...
Sync v5 -> v6
2024-03-02 18:30:31 +01:00
Dominik
d4792bb70c
Merge pull request #1886 from pi-hole/tweak/allow_adlist_dups
...
Allow adlist duplicates
2024-03-02 18:28:41 +01:00
yubiuser
661d9e3be0
Merge pull request #1897 from pi-hole/dependabot-github_actions-development-v6-github_action-dependencies-b4913446bb
...
Bump the github_action-dependencies group with 3 updates
2024-03-02 12:49:10 +01:00
dependabot[bot]
a1d6f85bf1
Bump the github_action-dependencies group with 3 updates
...
Bumps the github_action-dependencies group with 3 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ), [Wandalen/wretry.action](https://github.com/wandalen/wretry.action ) and [actions/download-artifact](https://github.com/actions/download-artifact ).
Updates `docker/setup-buildx-action` from 3.0.0 to 3.1.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/v3.0.0...v3.1.0 )
Updates `Wandalen/wretry.action` from 1.4.4 to 1.4.5
- [Release notes](https://github.com/wandalen/wretry.action/releases )
- [Commits](https://github.com/wandalen/wretry.action/compare/v1.4.4...v1.4.5 )
Updates `actions/download-artifact` from 4.1.2 to 4.1.4
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v4.1.2...v4.1.4 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github_action-dependencies
- dependency-name: Wandalen/wretry.action
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github_action-dependencies
- dependency-name: actions/download-artifact
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github_action-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-03-02 10:26:16 +00:00
Dominik
bffd2bd4ba
Merge pull request #1892 from pi-hole/fix/dnsmasq_resource_warning
...
Fix spurious "resource limit exceeded" messages
2024-02-20 05:27:37 +01:00
DL6ER
cf06e53872
Update embedded dnsmasq version to 2.90+1
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-19 13:59:52 +01:00
Simon Kelley
157b589391
Fix spurious "resource limit exceeded" messages.
...
Replies from upstream with a REFUSED rcode can result in
log messages stating that a resource limit has been exceeded,
which is not the case.
Thanks to Dominik Derigs and the Pi-hole project for
spotting this.
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-19 13:59:52 +01:00
DL6ER
d5cf5799c1
Merge branch 'development' into merge-v5-6
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-17 16:43:15 +01:00
DL6ER
d74d2a1e1c
Improve config migration logging
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-17 16:27:40 +01:00
DL6ER
750db7ecda
Merge branch 'development-v6' into tweak/allow_adlist_dups
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 21:06:43 +01:00
Dominik
41725fd343
Merge pull request #1887 from pi-hole/tweak/apppw_descrition
...
Improve description of GET /auth/app endpoint
2024-02-13 21:05:42 +01:00
Dominik
6681804b3c
Merge pull request #1875 from pi-hole/update/dnsmasq
...
Update embedded dnsmasq to v2.90
2024-02-13 20:21:55 +01:00
Dominik
2582043a2d
Apply code review
...
Co-authored-by: RD WebDesign <github@rdwebdesign.com.br >
Signed-off-by: Dominik <DL6ER@users.noreply.github.com >
2024-02-13 19:58:27 +01:00
DL6ER
a326d80869
Update dnsmasq version to 2.90
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 17:10:05 +01:00
DL6ER
2c7c19c1ae
Update expected dnsmasq warnings
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 17:07:17 +01:00
DL6ER
96f4acb516
Add documentation for automatically added new DNSSEC-related metrics
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 17:03:05 +01:00
Simon Kelley
c95816f3b9
Reverse suppression of ANY query answer logging.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:46:14 +01:00
Simon Kelley
4b351cbe36
Add --dnssec-limits option.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:45:54 +01:00
Simon Kelley
cb577f318e
Better allocation code for DS digest cache.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:45:19 +01:00
Simon Kelley
dcd12a2be6
Better stats and logging from DNSSEC resource limiting.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:45:12 +01:00
Simon Kelley
84161ed295
Overhaul data checking in NSEC code.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:44:06 +01:00
Simon Kelley
1dbbdc96ca
Rework validate-by-DS to avoid DoS vuln without arbitrary limits.
...
By calculating the hash of a DNSKEY once for each digest algo,
we reduce the hashing work from (no. DS) x (no. DNSKEY) to
(no. DNSKEY) x (no. distinct digests)
The number of distinct digests can never be more than 255 and
it's limited by which hashes we implement, so currently only 4.
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:43:59 +01:00
Simon Kelley
b5e7dd448b
Update EDE code -> text conversion.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:43:11 +01:00
Simon Kelley
f141efdeba
Parameterise work limits for DNSSEC validation.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:43:03 +01:00
Simon Kelley
d92159a836
Fix error introduced in 635bc51cac3d5d7dd49ce9e27149cf7e402b7e79
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:40:32 +01:00
Simon Kelley
0b9e5543d2
Measure cryptographic work done by DNSSEC.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:40:27 +01:00
Simon Kelley
ddf44bf916
Update NSEC3 iterations handling to conform with RFC 9276.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:38:55 +01:00
Simon Kelley
aa565b1dff
Update header with new EDE values.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:38:50 +01:00
Simon Kelley
ebbfb893bd
Protection against pathalogical DNSSEC domains.
...
An attacker can create DNSSEC signed domains which need a lot of
work to verfify. We limit the number of crypto operations to
avoid DoS attacks by CPU exhaustion.
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 16:38:46 +01:00
DL6ER
81a1da69cb
Improve description of GET /auth/app endpoint
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 14:52:33 +01:00
DL6ER
8325db3cc8
Set REPLY of queries that failed DNSSEC validation to NONE (if not already set elsehow)
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 14:28:47 +01:00
DL6ER
fbd7aa7761
Check for UNKNOWN status and replies during CI testing
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 10:38:30 +01:00
DL6ER
8b3c39015d
Add RFC 8482 filtering (Providing Minimal-Sized Responses to DNS Queries That Have QTYPE=ANY) by default
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 09:51:53 +01:00
DL6ER
7a919cbf59
Allow narrowing down the (ad)list type using the (optional) query parameter ?type={allow,block}
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 08:42:08 +01:00
DL6ER
f6fb93e997
Update embedded dnsmasq version to 2.90test4
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 07:19:15 +01:00
Simon Kelley
75648b4def
Make --filter-rr=ANY filter the answer to ANY queries.
...
Thanks to Dominik Derigs for an earlier patch which inspired this.
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 07:15:03 +01:00
Simon Kelley
8cdead96a5
Tweak logging and special handling of T_ANY in rr-filter code.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-13 07:12:25 +01:00
DL6ER
e3e839880e
Merge branch 'development-v6' into update/dnsmasq
2024-02-13 07:12:16 +01:00
Dominik
9e3ccd917d
Merge pull request #1797 from pi-hole/new/multi_revServer
...
Add support for multiple reverse servers
2024-02-11 06:52:31 +01:00
Dominik
54262aeba2
Merge pull request #1878 from pi-hole/fix/debug_api_description
...
Fix debug.api config options description.
2024-02-10 20:56:25 +01:00
Dominik
5940c62763
Merge pull request #1719 from pi-hole/tweak/env_vars_list
...
Check all env vars and suggest alternatives for misspelled keys
2024-02-10 16:21:42 +01:00
yubiuser
c994dad4f5
Merge pull request #1880 from pi-hole/dependabot-github_actions-development-v6-github_action-dependencies-d9773afac8
...
Bump the github_action-dependencies group with 3 updates
2024-02-10 12:36:38 +01:00
dependabot[bot]
c2f690b3ab
Bump the github_action-dependencies group with 3 updates
...
Bumps the github_action-dependencies group with 3 updates: [Wandalen/wretry.action](https://github.com/wandalen/wretry.action ), [actions/upload-artifact](https://github.com/actions/upload-artifact ) and [actions/download-artifact](https://github.com/actions/download-artifact ).
Updates `Wandalen/wretry.action` from 1.3.0 to 1.4.4
- [Release notes](https://github.com/wandalen/wretry.action/releases )
- [Commits](https://github.com/wandalen/wretry.action/compare/v1.3.0...v1.4.4 )
Updates `actions/upload-artifact` from 4.3.0 to 4.3.1
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v4.3.0...v4.3.1 )
Updates `actions/download-artifact` from 4.1.1 to 4.1.2
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v4.1.1...v4.1.2 )
---
updated-dependencies:
- dependency-name: Wandalen/wretry.action
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github_action-dependencies
- dependency-name: actions/upload-artifact
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github_action-dependencies
- dependency-name: actions/download-artifact
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github_action-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2024-02-10 11:00:33 +00:00
DL6ER
ec37efd77f
Fix debug.api config options description.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-10 09:34:25 +01:00
Dominik
82f8abe71f
Merge pull request #1877 from pi-hole/tweak/dnssec_default
...
DNSSEC validation should not be enabled by default in v6
2024-02-09 22:45:57 +01:00
DL6ER
16cc1027fb
DNSSEC validation should not be enabled by default - it wasn't in v5, either. The reason for this is that it may be causing issues on devices with broken/missing RTCs where NTP time synchronization relies on DNS resolution
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2024-02-09 21:51:31 +01:00