Created attachment 183666 [details] contrib/unbound/iterator/iter_hints.c.patch
Should be upstreamed to unbound and looped back, I think.
(In reply to Conrad Meyer from comment #1) That's right, I think so, but contact me upstream. :-)
(In reply to Conrad Meyer from comment #1) > Should be upstreamed to unbound and looped back, I think. These changes have already been committed upstream. We're just not tracking them very closely.
I am not sure they warrant an EN to get them into the current releases. Let me explain, this list is only used once, when starting the daemon, during the priming phase, to get a list that may be more current. Once that is done, the list is no longer used. I would start worrying about it not being current if 2/3rd of the addresses were wrong. Especially as with DNSSEC, it is not possible to get a corrupted version of the root zone name-servers list.
(In reply to Mathieu Arnold from comment #4) So, is this difference unnecessary at this stage?
It's really not a big deal. It's just one address out of two dozen. It will be updated with the next vendor import.