Re: djbdns: Current recommended patches?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
I am putting together a trusted distribution of patches and will soon announce the site and the distribution. There will be more than just DJBDNS...probably qmail, Open Development Environment, DCE, and other things. Probably a merge of daemontools with the DCE(afs) BOS tools. By trusted, I mean that everyone submitting patches will have references and background. No anonymous people running distributions. Patches will only be accepted from identifiable, trustable sources. Bug demonstrations can be submitted anonymously. This distibution will NOT, under ANY circumstances, accept anonymous or dubious patches purporting to enhance performance but which affect security parameters. For example, we will not be accepting the Kaminsky/Day/King patches, or patches from Mark Johnson (possible sock puppet, having no background or job history or references, nor any history whatsoever prior to 2007 where he first posted on the qmail list). My company is incorporated, has a board of directors, and will be a responsible and trustworthy vendor. --Dean On 18 May 2009, Andrew Richards wrote: > Hi, > > I'm looking afresh at djbdns to establish a baseline of recommended > patches; I'm not so interested in extra features - tinydns.org has a > generous selection for that and different people will have different > requirements - rather, what makes for a good djbdns basic setup. Given > some recent posts and debates on the list I thought I needed to check > what's now most appropriate. > > This overlaps somewhat with Mark Johnson's work on his zinq project (I > note he's been exploring what patches are out there); I confess that > I've not looked at zinq; for now I prefer a compiled from source > approach and avoiding autoconf (personal preference, I note the list > had an extensive exchange on this issue some time ago). > > I've put my thoughts below, I'd appreciate yours, esp. any views on > the production-readiness of the various patches mentioned; noting that > many of the authors of these patches are on the list their input would > be particularly valued. > > For patches referenced on the list I've used (e.g.) GMANE/13864 > to refer to > http://article.gmane.org/gmane.network.djbdns/13864 > > These patches seem to have no downsides as well as being very short: > > - (tinydns.org) errno patch, or updating conf-cc as per Dan's > instructions > > - (tinydns.org) SIGPIPE patch > > - (GMANE/13864) Matthew Dempsky's security patch > > - (tinydns.org) Updating the list of root servers - Jonathan de Boyne > Pollard instructions link. > > These patches seem worthwhile: > > - Matthew Dempsky's patch to increase the max. UDP packet size: > GMANE/13537. This seems preferable to Sami Farin's fallback-to-TCP > patch GMANE/13522. I guess both could be used, but that would > assume that answers > 4K in size will be received, and I also note > some possible improvements to the fallback-to-TCP patch GMANE/13525 > that would be good to have before using it. Both are currently > one-liners which is very appealing. > > - (tinydns.org) Lennert Baytenheck "one second" patch to improve > tinydns efficiency > > - (www.your.org/dnscache/) Jeff King's SOA caching patch: > anti-cache-poisoning measure > > - (www.your.org/dnscache/) Merge identical outgoing requests: > anti-cache-poisoning measure. As Jeff King the author notes > GMANE/14017, this includes a linear search of outstanding requests, > which is inefficient; there's also an issue with lame delegations > (GMANE/13862) which makes me wonder if this is still a > work-in-progress (GMANE/13925)...? > > Finally season to taste with tinydns.org linked patches for one's > particular DNS needs (additional RR types etc). > > Thank you in advance for any thoughts on the above. > > Andrew. > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000