Bug 241613 - dns/bind914: add option for using accf_dns (dnsready accept filter)
Summary: dns/bind914: add option for using accf_dns (dnsready accept filter)
Status: New
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Mathieu Arnold
URL: https://lists.isc.org/pipermail/bind-...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-10-31 09:46 UTC by Eugene Grosbein
Modified: 2019-11-12 16:43 UTC (History)
0 users

See Also:
bugzilla: maintainer-feedback? (mat)
eugen: maintainer-feedback?


Attachments
add ACCFDNS (931 bytes, patch)
2019-10-31 09:46 UTC, Eugene Grosbein
eugen: maintainer-approval?
Details | Diff
files/extrapatch-interfacemgr.c (461 bytes, patch)
2019-10-31 09:47 UTC, Eugene Grosbein
eugen: maintainer-approval?
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Eugene Grosbein freebsd_committer 2019-10-31 09:46:21 UTC
Created attachment 208727 [details]
add ACCFDNS

Let's add new option ACCFDNS to the port dns/bind914 that allows BIND to prefer accf_dns over accf_data, if accf_dns is available. The patch was submitted upstream by David Malone 7 years ago but ignored:

https://lists.isc.org/pipermail/bind-users/2012-October/088862.html

The option is disabled by default, so default built is not affected and PORTREVISION not changed.
Comment 1 Eugene Grosbein freebsd_committer 2019-10-31 09:47:43 UTC
Created attachment 208728 [details]
files/extrapatch-interfacemgr.c
Comment 2 Mathieu Arnold freebsd_committer 2019-11-12 15:42:50 UTC
I do not think this is a good idea.  DNS is hard, and I do not feel confident about anything else than BIND9 deciding if what it receives is a valid DNS packet.
Comment 3 Eugene Grosbein freebsd_committer 2019-11-12 16:43:36 UTC
The option is disabled by default, why don't we add it for users that know what they do?