|Summary:||dns/bind914: add option for using accf_dns (dnsready accept filter)|
|Product:||Ports & Packages||Reporter:||Eugene Grosbein <eugen>|
|Component:||Individual Port(s)||Assignee:||Mathieu Arnold <mat>|
|Severity:||Affects Only Me||CC:||rene|
Description Eugene Grosbein 2019-10-31 09:46:21 UTC
Created attachment 208727 [details] add ACCFDNS Let's add new option ACCFDNS to the port dns/bind914 that allows BIND to prefer accf_dns over accf_data, if accf_dns is available. The patch was submitted upstream by David Malone 7 years ago but ignored: https://lists.isc.org/pipermail/bind-users/2012-October/088862.html The option is disabled by default, so default built is not affected and PORTREVISION not changed.
Comment 1 Eugene Grosbein 2019-10-31 09:47:43 UTC
Created attachment 208728 [details] files/extrapatch-interfacemgr.c
Comment 2 Mathieu Arnold 2019-11-12 15:42:50 UTC
I do not think this is a good idea. DNS is hard, and I do not feel confident about anything else than BIND9 deciding if what it receives is a valid DNS packet.
Comment 3 Eugene Grosbein 2019-11-12 16:43:36 UTC
The option is disabled by default, why don't we add it for users that know what they do?
Comment 4 Rene Ladan 2020-04-30 11:05:38 UTC
Is this relevant for dns/bind916 too?