Fwd: Please correct http://linuxmafia.com/faq/Network_Other/dns-servers.html

Mark Johnson <[email protected]> Wed, 28 Apr 2010 20:16:15 -0500
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
---------- Forwarded message ----------
From: Rick Moen <[email protected]>
Date: Wed, Apr 28, 2010 at 6:09 PM
Subject: Re: Please correct
http://linuxmafia.com/faq/Network_Other/dns-servers.html
To: Gerrit Pape <[email protected]>
Cc: Mark Johnson <[email protected]>, Matthew Dempsky <[email protected]>


Hi, Gerrit!  Thank you for the mail, and thank you for maintaining
Debian's djbdns/dbndns (and for other good work, such as your
exceptionally useful manpages).


Quoting Gerrit Pape ([email protected]):

> Cc: [email protected]

No, sorry, I am not on that mailing list.  Therefore, I am not
continuing your CC.  However, I'm CCing a couple of people mentioned.
(My apologies to them if they lack time or interest.)


Citations below relate to contents of
http://ftp.de.debian.org/debian/pool/main/d/djbdns/djbdns_1.05-8.diff.gz,
which you may recall is the source package's set of diffs per
http://packages.debian.org/source/sid/djbdns


> http://linuxmafia.com/faq/Network_Other/dns-servers.html states:
> > Debian djbdns/dbndns: (link) Debian developer Gerrit Pape maintains two
> > Debian binary packages (dbndns, djbdns) based on one Debian source
> > package (djbdns). Pape applies these changes to Bernstein's v. 1.05:
> >
> > In both binary packages "djbdns" and "dbndns":
> > Supplied manpages (by Gerrit Pape).
>
> Okay.
>
> > Patched to use glibc, system errno.h headers.

I'm confused:  This change (from
http://ftp.de.debian.org/debian/pool/main/d/djbdns/djbdns_1.05-8.diff.gz)
is not using glibc?

+  * debian/rules: remove target configure:; use glibc by default instead
+    of dietlibc; install programs into /usr/bin/.


This is not using errno.h headers?

+  * debian/rules: use 'gcc -O2 -g -include /usr/include/errno.h' for
+    conf-cc.



> No, the packages simply follow upstream's installation instructions, and
> do "echo 'gcc -O2 -g -include /usr/include/errno.h' >conf-cc" before
> running "make".

Perhaps I'm missing something hat seems to boil down, in effect on Linux
systems, to using system errno.h headers.


> > Patched dnscache to update obsolete root nameservers list.
>
> No, there's no such patch.  The packages adjust /etc/dnsroots.global, no
> changes to dnscache are applied.

How would you better phrase the effect of
+  * dbndns/diff/0001-hier.c-don-t-install-etc-dnsroots.global.diff
, please?


> > Patched to support parallel build through "make -j".
>
> No, I don't know about such a patch.

How would you better characterise this?

+  * debian/implicit: add proper dependencies to support 'parallel build'
+    through make -j (thx Daniel Schepler for the patch).



> > Patched to install binaries into /usr/bin.
>
> No, the packages simply do "echo /usr >conf-home" before running "make".

How would you better characterise this?  Is this patch item not
installing programs into /usr/bin?

+  * debian/rules: remove target configure:; use glibc by default instead
+    of dietlibc; install programs into /usr/bin/.


> > Patched to no longer require daemontools, ucspi-tcp.
>
> Not at all, I wouldn't do that.

How would you better characterise this?  Doesn't this change remove the
Depends on daemontools and ucspi-tcp, and change them to Recommends?

+  * debian/control: no longer Recommends: djbdns-doc; no longer Depends:
+    daemontools, ucspi-tcp, make, but Recommends: them; Recommends:
+    daemontools-run | runit; Depends: ${shlibs:Depends}.



> > Patched dnscache to update obsolete root nameservers list.
>
> DUP!

Thank you.  Fixed.


> > Patched axfrdns and tinydns to correct a security-damaging bug in
> > large-packet TCP data handling that permits a limited form of cache
> > poisoning.
>
> I don't grasp this, axfrdns and tinydns aren't caches.

(The wording doesn't _allege_ that axfrdns and tinydns are caches, and
such was not my meaning.)  How would you better characterise this patch
(likewise included in the Debian patch collection)?
djbdns-1.05/debian/diff/0002-djbdns-misformats-some-long-response-packets-patch-a.diff

You will find within
http://ftp.de.debian.org/debian/pool/main/d/djbdns/djbdns_1.05-8.diff.gz
(the Debian patch collection) a long e-mail from Matthew Dempsky
<[email protected]> (CC'd) dated March 2, 2009, in which he explains
what that patch does and how cache poisioning can occur without it.


> If you mean http://article.gmane.org/gmane.network.djbdns/13864, yes, I
> include this patch recommended by the upstream author in both packages.
> If not, no, I don't know about such a patch.

It's been a bit over a year since I read Mr. Dempsky's comments, and
I don't currently have time to re-read them and the patch to verify, but
that does seem on initial reading to be the same patch to which Prof.
Bernstein refers in the gmane.org link you cite.



> > Patched dnscache to set initial cache size to 1*10^9 bytes, and triple
> > the upstream code's cache limit to 3*10^9 bytes.
>
> No, I don't know about such a patch.

Hmm, odd.  Might have been a copy-and-paste error from elsewhere in the
referenced page's HTML.  Removed.  Thanks.


> > Applied to binary package "dbndns" only:
> > Patched tinydns to add native IPV6 support.
>
> + Patched to allow a maximum of 20 concurrent outgoing SOA queries
>
> But I'll possibly remove the patch again, it was created to convince the
> Debian security team, but that failed.

Note to that effect added.  Thanks again for your mail, and for any
suggestions for better wording.

--
Rick Moen           Well, my terminal's locked up, and I ain't got any mail,
[email protected] And I can't recall the last time my program didn't fail;
McQ!  (4x80)        I've got stacks in my structs, I've got arrays in my queues,
                   I've got the:  Segmentation violation -- Core dumped blues.