Bug 241613

Summary: dns/bind914: add option for using accf_dns (dnsready accept filter)
Product: Ports & Packages Reporter: Eugene Grosbein <eugen>
Component: Individual Port(s)Assignee: Mathieu Arnold <mat>
Status: New ---    
Severity: Affects Only Me CC: rene
Priority: --- Flags: bugzilla: maintainer-feedback? (mat)
eugen: maintainer-feedback?
Version: Latest   
Hardware: Any   
OS: Any   
URL: https://lists.isc.org/pipermail/bind-users/2012-October/088862.html
Description Flags
eugen: maintainer-approval?
files/extrapatch-interfacemgr.c eugen: maintainer-approval?

Description Eugene Grosbein freebsd_committer 2019-10-31 09:46:21 UTC
Created attachment 208727 [details]

Let's add new option ACCFDNS to the port dns/bind914 that allows BIND to prefer accf_dns over accf_data, if accf_dns is available. The patch was submitted upstream by David Malone 7 years ago but ignored:


The option is disabled by default, so default built is not affected and PORTREVISION not changed.
Comment 1 Eugene Grosbein freebsd_committer 2019-10-31 09:47:43 UTC
Created attachment 208728 [details]
Comment 2 Mathieu Arnold freebsd_committer 2019-11-12 15:42:50 UTC
I do not think this is a good idea.  DNS is hard, and I do not feel confident about anything else than BIND9 deciding if what it receives is a valid DNS packet.
Comment 3 Eugene Grosbein freebsd_committer 2019-11-12 16:43:36 UTC
The option is disabled by default, why don't we add it for users that know what they do?
Comment 4 Rene Ladan freebsd_committer 2020-04-30 11:05:38 UTC
Is this relevant for dns/bind916 too?
Comment 5 Eugene Grosbein freebsd_committer 2020-04-30 11:24:28 UTC
(In reply to Rene Ladan from comment #4)

It is relevant for bind916 even more, because this version disabled usage of dataready accept filter too. However, the patch needs correction. I can correct it if maintainer is willing to accept the idea.