Skip to content

ci(bind): update bind920 to 9.20.27 - #82

Merged
bryanwieg merged 1 commit into
masterfrom
sync/bind920/9.20.27-0
Aug 28, 2026
Merged

bryanwieg merged 1 commit into
masterfrom
sync/bind920/9.20.27-0

Conversation

@bryanwieg

@bryanwieg bryanwieg commented Aug 28, 2026 •

Copy link
Copy Markdown
Collaborator

BIND Candidate Assessment

BIND 9.20.26_2 to 9.20.27 is classified as routine. Signals: none. Maintainer review is required before publication.

  • classification: routine
  • publication: manual maintainer action required

Signals

  • none

Upstream BIND Changes

  • 74d0754dbe Update BIND version for release
  • 476b0b8e33 new: doc: Prepare documentation for BIND 9.20.27
  • 4e351ec4fa Tweaks and reword release notes
  • 14612228b0 Prepare release notes for BIND 9.20.27
  • 366b8251fa Generate changelog for BIND 9.20.27
  • 994c3bd432 [9.20] fix: usr: dnssec-signzone had a potential heap bounds overflow write
  • 31bcb67b44 Grow arrays in signset if key->index is too big
  • b166eefd0a [9.20] fix: test: Fix sign-compare build error in time_test on i386
  • 6d5298f347 Fix sign-compare build error in time_test on i386
  • 4cfed63c3e [9.20] chg: test: Convert the digdelv system test from shell to pytest
  • fea7679427 Skip Python files in the CI dig output check
  • 7d85528426 Drop executable-availability skips from the digdelv tests
  • 24e91782c6 Gate the dig source-address crash check on IPv6 availability
  • c5a69a4a72 Require PyYAML for the digdelv system test
  • b7b945c37f Migrate digdelv delv +ns checks to pytest, dropping tests.sh
  • d510b21b80 Migrate digdelv delv checks to pytest
  • 293716bd3f Migrate digdelv mdig checks to pytest
  • a9799087ea Migrate digdelv dig +yaml structure checks to pytest
  • c036e1bd0d Migrate digdelv dig failover checks to pytest
  • 25524e3da4 Migrate digdelv dig +subnet checks to pytest
  • cc600bfab6 Migrate digdelv dig EDNS checks to pytest
  • a9f3e419cb Migrate digdelv dig formatting checks to pytest
  • 1e9bf52d60 Migrate digdelv nslookup/host/nsupdate checks to pytest
  • b8d56c45be [9.20] chg: test: Use asyncserver in the reclimit system test
  • 3076dc2447 Require IPv6 in the reclimit system test
  • d2c2334ca1 Reimplement 'reclimit/ans2' server using ControllableAsyncServer
  • c34625dfbb Reimplement 'reclimit/ans4' using ControllableAsyncServer
  • 80031ae622 Reimplement 'reclimit/ans7' server using AsyncDnsServer
  • 0ae190356a Add common parts of reclimit test custom servers
  • 9d6855ef73 [9.20] new: dev: Add more unit tests for isc_time API
  • cdab21acb4 Make isc_time_nowplusinterval consistent with other functions
  • 987cafcb36 Add more unit tests for isc_test API
  • 51ea983297 Add more validity checks to the isc_time API
  • cb40fb91fa [9.20] chg: usr: Batch qp transaction for RPZ updates
  • 9bb04946c6 Atomic rpz shutdown
  • df467cd22c Split rpz maint_lock into two
  • 358b172ccd Move rpz, db an dbversion to the baton
  • fc150c3351 Delete optimistically from rpz nodes hashtable
  • 1cc316de7d Batch qp transaction
  • f6daf0864f Increase lock scope in rpzs construction
  • 75176a854f [9.20] fix: test: Wait for the committed NSEC3 chain state in the nsec3 tests
  • 3e78df75cc Wait for the committed NSEC3 chain state in the nsec3 tests
  • 20f5580e01 [9.20] fix: usr: Fix compilation on GNU/Hurd
  • 8214308f4c Include <isc/dir.h> for GNU/Hurd compilation
  • 8cd87a016d Define IOV_MAX if not already defined
  • 446e815e09 Remove UNUSED for non existing arguments
  • db3564f44a Only compile need_rescan if RTM_NEWADDR and RTM_DELADDR are defined
  • 9c459b1854 [9.20] fix: usr: Fix NULL pointer dereference in dnstap-read
  • f3edf0e91a Check that the message is non NULL in dns_dt_parse
  • 8c995dd60c [9.20] chg: test: Rewrite the tcp system test in Python
  • 8d50f0119c Remove forgotten compatibility check
  • f47d6ed1ff Port the long TCP stream test to Python
  • 62b73e34fc Port TCP high-water checks to Python
  • ecaeb8ced5 Port TCP request statistics checks to Python
  • 747e4cf7c9 Refactor the existing Python TCP system tests
  • f8f8edba3a [9.20] fix: nil: Address out of bounds memory read in dnstap-read
  • e3916f08ba Address out of bounds memory read in dnstap-read
  • c4e53b59b2 [9.20] fix: dev: dig with IDN output could leak memory on ISC_R_NOSPACE retry
  • e910f2f73d dig with IDN output could leak memory on ISC_R_NOSPACE retry
  • 0964e985c2 Backport CLEANUP macro to <isc/util.h>
  • 17f0828b46 [9.20] fix: usr: Treat non canonical RPZ prefixes as any other failure
  • ae7ba2f3c4 Report RPZ prefixes in not canonical form as error
  • 8bde9318f6 [9.20] fix: usr: Restore SMF support on Solaris and illumos
  • 72050ae334 Restore SMF support in the build system
  • 4c01bf9e17 Use a private memory context for the SMF instance check
  • a35870391a Add missing putnull() to named_smf_add_message()
  • 78265c8f6f [9.20] fix: dev: Change catz coo locking
  • 4a21d84b67 Split lock coos check design
  • 2778a2dc57 [9.20] new: test: Add pyyaml to system test requirements
  • fd625250a0 Add pyyaml to system test requirements
  • 467c9a3ad6 [9.20] rem: ci: Drop FreeBSD 13 support
  • b479ca5c9f Drop FreeBSD 13 support
  • 14884eab7e [9.20] fix: test: Drop a redundant racy check in fetchlimit test
  • 6ef39d2d6f Drop a redundant racy check in fetchlimit test
  • 86ad6866ee [9.20] fix: dev: Restore arc4random() detection dropped in the v9.21.14 merge
  • e7d6f50c79 Restore arc4random() detection dropped in the v9.20.15 merge
  • d825a3ab98 [9.20] new: test: Mark each test's boundaries in the named instance logs
  • 99b3dd734f Mark each test's boundaries in the named instance logs
  • a6b29ea8b7 Integrate the Python RNDC client into isctest
  • d63b0835ad Rework the Python RNDC client API around isctest conventions
  • af725207aa Add type annotations to rndc.py
  • 2ae1a1a6fd Align rndc.py naming with project conventions
  • afea425edb Port rndc.py to Python 3.10 idioms
  • 4292d89865 Sort rndc.py imports with ruff
  • eba5992cef Format rndc.py with black
  • 2414497b85 Use the standard license header in the imported rndc.py
  • 92b79c021a Import rndc.py from the python-rndc project verbatim
  • 3f3c82292c [9.20] fix: dev: Use memmove in isc_sockaddr_fromin/isc_sockaddr_fromin6
  • b09061f92f Add a new check in the proxyheader unit test
  • 9176d29cd2 Use memmove in isc_sockaddr_fromin/isc_sockaddr_fromin6
  • f3229eff8b [9.20] chg: test: Deduplicate controls configuration in named.conf test templates
  • 347ba21b01 Cover quoted key names in checkconf
  • 7be519224e Mark the configs that deliberately keep a custom controls config
  • 86072d2786 Replace empty controls statements with the controls template
  • a91ead0b03 Provide a control channel on named instances that had none
  • feb630f2ab Use controls template in named configs where rndc.key was included
  • a3984f07d4 Use controls template in named configs where rndc key was inlined
  • a6cea6f0a3 Fix controls statements bound to another instance's address
  • 879a383ef1 [9.20] fix: usr: Treat an unusable NSEC3 chain as a verification failure
  • af9ee4af84 Treat unusable NSEC3PARAM as a verification failure
  • ce17016071 Allow null nameserver for jinja2 test-zone templates
  • bedab84c14 Merge tag 'v9.20.26' into bind-9.20
  • 65d1776959 [9.20] fix: usr: dig +yaml producing invalid YAML when a lookup fails
  • 843d8b7a7f Test that +short does not leak the ";; " comments
  • 77298643a9 Don't emit comments when +short form is enabled
  • f688fdf8bb Don't print dig's startup banner with +nocmd when the lookup fails
  • c86061b43b Suppress the dig startup banner in +yaml error output
  • 566e701827 [9.20] new: usr: Disclose active Negative Trust Anchors with Extended DNS Error 33
  • bf6062daae Test Negative Trust Anchor disclosure via Extended DNS Error 33
  • c837990c20 Disclose Negative Trust Anchors with Extended DNS Error 33
  • 0a8829e97f chg: doc: Set up version for BIND 9.20.27
  • 37f7b3f583 Update BIND version to 9.20.27-dev
  • 932581b74b [9.20] fix: usr: Unterminated OpenSSL private-key Label: field can be read past its parser buffer
  • 637518c29c Malformed Label: data in .private files was not detected
  • 4b9db54911 [9.20] fix: test: Increase timeout for zone update in multisigner test
  • 6c43a011a5 Increase timeout for zone update in multisigner test
  • 89dc24eb6f [9.20] fix: test: Extend the check_dnssec_verify retry window to 60 seconds
  • a5972c23cd Extend the check_dnssec_verify retry window to 60 seconds
  • 5c1d3df49c [9.20] fix: dev: MacOS byte swapping macros already defined
  • 6d8ea15c73 Don't redefine the byte swap macros if already defined
  • 5dac280232 [9.20] fix: test: cdnxdomain test is failing
  • eff7130965 cdnxdomain test is failing on some platforms
  • ef651c9370 [9.20] new: dev: Add development guidance for AI coding agents under .agents/skills/
  • 0c3baab5ff Add Claude Code skills symlink
  • 5e6964bd70 License the .agents/ contents under MPL-2.0
  • 0dabae6659 Add the bind-mr-description agent skill
  • e01bab0fcf Add the bind-commit agent skill
  • 6787385c63 Add the per-loop-affinity agent skill
  • 567f5928a1 Add the struct-layout-analysis agent skill
  • 0a10e1a3ce Add the lttng-tracing-root-cause-analysis agent skill
  • 8efa3aa765 Add the rcu-mutation agent skill
  • 0fd4829a71 Add the isc-mem-allocator agent skill
  • 2a6c59797f [9.20] fix: test: Replace python deprecated datetime utc functions
  • c143afb19e Replace python deprecated datetime utc functions
  • f777451d26 [9.20] fix: usr: Properly prevent TSIG generation command line injection attacks
  • 60a6a80310 Add dns_name_totext unit test
  • 43bdde2bd4 Update tests_rndc_confgen.py to show escaped double quotes
  • 5d3586b789 Allow all valid key names
  • fabd89b32a Add DNS_NAME_QUOTED flag for dns_name_totext()
  • 0baaddd096 [9.20] fix: usr: Ensure NSEC authority does not cross zonecut boundary
  • 4d044fe646 Add a system test for the grandparent NSEC downgrade
  • ab4348822c Ensure NSEC authority does not cross zonecut boundary
  • 65cdb7c761 [9.20] chg: dev: Pass the work callback result to the done callback
  • 3f6c833b02 Pass the work callback result to the done callback
  • 5f8f1b9e3e [9.20] chg: test: Replace prereq.sh files with isctest.mark
  • 501a839286 Move the cipher_suites prereq.sh check to a marker
  • 9fabc46469 Remove obsolete ixfr_nonminimal prereq.sh file
  • e71c9fa061 Remove prereq.sh support from the system test runner
  • 7cde7749f6 Move the statschannel prereq.sh check to a marker
  • 06687f8c2f Gate enginepkcs11 with the softhsm2_environment marker
  • 16bbb7f256 Move the pkcs11-provider prereq.sh check to a marker
  • 021508d3bf Move FIPS-DH prereq.sh checks to a with_fips_dh marker
  • 939c809a74 Move gssapi prereq.sh checks to a with_gssapi marker
  • 91347bf383 Move the cpu prereq.sh check to a with_cpu_affinity marker
  • 7dbc20f278 Move the eddsa prereq.sh check to a with_eddsa marker
  • 9a37fd2d4e Move TSAN prereq.sh checks to a without_tsan marker
  • e810dea4bd Move the geoip2 prereq.sh check to a with_geoip2 marker
  • 6942e2049b Move libnghttp2 prereq.sh checks to a with_libnghttp2 marker
  • f980a68fe2 Move Perl-module prereq.sh checks to pytest markers
  • c71c7b6d6f Remove obsolete Perl module prereq.sh files
  • 2687d16ed2 [9.20] fix: usr: Negative caching stopped working with stale-answer-client-timeout 0
  • 4fa5b6a95a Test that a fresh negative cache entry is not refreshed
  • 4afd5b0462 Only refresh negative cache entries that are actually stale
  • f3230783c2 chg: doc: Set up version for BIND 9.20.26
  • 17457add58 Update BIND version to 9.20.26-dev

FreeBSD Ports Changes

  • 0760935063ca dns/bind9*: building with heimdal is broken on 15+
  • 07609280d770 dns/bind920: update to 9.20.27

Candidate Inputs

  • FreeBSD Ports commit: 9e15a0d76575d39aa13cdcca5f57c471a87efdba
  • Previous FreeBSD Ports commit: 343e9b366f371df755622e1680b59d998e5778fd
  • New BIND version: 9.20.27
  • Publication: not performed by this workflow

@github-actions
github-actions Bot force-pushed the sync/bind920/9.20.27-0 branch from 1281081 to 255feab Compare August 28, 2026 03:37
@github-actions
github-actions Bot force-pushed the sync/bind920/9.20.27-0 branch from 255feab to 2456cf6 Compare August 28, 2026 03:51
@bryanwieg
bryanwieg merged commit 01f70b8 into master Aug 28, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant