Created attachment 208727 [details]
Let's add new option ACCFDNS to the port dns/bind914 that allows BIND to prefer accf_dns over accf_data, if accf_dns is available. The patch was submitted upstream by David Malone 7 years ago but ignored:
The option is disabled by default, so default built is not affected and PORTREVISION not changed.
Created attachment 208728 [details]
I do not think this is a good idea. DNS is hard, and I do not feel confident about anything else than BIND9 deciding if what it receives is a valid DNS packet.
The option is disabled by default, why don't we add it for users that know what they do?