GNU bug report logs - #68620
[PATCH 1/2] gnu: knot-resolver: Re-enable default DNSSEC trust anchors.

Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.

Package: guix-patches; Reported by: Leo Nikkilä <hello@HIDDEN>; Keywords: patch; Done: Dale Mellor <guix-devel-0brg6a@HIDDEN>; Maintainer for guix-patches is guix-patches@HIDDEN.

Message received at 68620 <at> debbugs.gnu.org:


Received: (at 68620) by debbugs.gnu.org; 23 Apr 2024 17:46:26 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Tue Apr 23 13:46:25 2024
Received: from localhost ([127.0.0.1]:53480 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1rzKDh-00068s-Dv
	for submit <at> debbugs.gnu.org; Tue, 23 Apr 2024 13:46:24 -0400
Received: from [195.15.247.228] (port=63359 helo=rdmp.org)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <guix-devel-0brg6a@HIDDEN>) id 1rzIe0-000057-4f
 for 68620 <at> debbugs.gnu.org; Tue, 23 Apr 2024 12:05:24 -0400
Received: from [127.0.0.1] (helo=[IPv6:::1])
 by rdmp.org with esmtp (Exim 4.96.1)
 (envelope-from <guix-devel-0brg6a@HIDDEN>) id 1rzIdb-000473-2c
 for 68620 <at> debbugs.gnu.org; Tue, 23 Apr 2024 16:04:56 +0000
Message-ID: <cd9491b81e7c87cdef9b35df347231d841102cf8.camel@HIDDEN>
Subject: Moved into 68621
From: Dale Mellor <"	guix-devel-0brg6a"@rdmp.org>
To: 68620 <at> debbugs.gnu.org
Date: Tue, 23 Apr 2024 17:04:55 +0100
Organization: DM Bespoke Computer Solutions Ltd
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
User-Agent: Evolution 3.48.4 
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 the administrator of that system for details.
 Content preview:  This patch belongs to issue 68621, closing here. 
 Content analysis details:   (1.3 points, 10.0 required)
 pts rule name              description
 ---- ---------------------- --------------------------------------------------
 -0.0 SPF_PASS               SPF: sender matches SPF record
 -0.0 SPF_HELO_PASS          SPF: HELO matches SPF record
 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
 0.0 FROM_ADDR_WS           Malformed From address
X-Debbugs-Envelope-To: 68620
X-Mailman-Approved-At: Tue, 23 Apr 2024 13:46:16 -0400
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: 0.3 (/)

This patch belongs to issue 68621, closing here.





Information forwarded to guix-patches@HIDDEN:
bug#68620; Package guix-patches. Full text available.
bug closed, send any further explanations to 68620 <at> debbugs.gnu.org and Leo Nikkilä <hello@HIDDEN> Request was from Dale Mellor <guix-devel-0brg6a@HIDDEN> to control <at> debbugs.gnu.org. Full text available.

Message received at 68620 <at> debbugs.gnu.org:


Received: (at 68620) by debbugs.gnu.org; 23 Apr 2024 16:21:58 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Tue Apr 23 12:21:57 2024
Received: from localhost ([127.0.0.1]:53105 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1rzIu3-00038D-To
	for submit <at> debbugs.gnu.org; Tue, 23 Apr 2024 12:21:57 -0400
Received: from [195.15.247.228] (port=63619 helo=rdmp.org)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <guix-devel-0brg6a@HIDDEN>) id 1rzIu0-00036Q-BX
 for 68620 <at> debbugs.gnu.org; Tue, 23 Apr 2024 12:21:53 -0400
Received: from [127.0.0.1] (helo=[IPv6:::1])
 by rdmp.org with esmtp (Exim 4.96.1)
 (envelope-from <guix-devel-0brg6a@HIDDEN>) id 1rzItc-00047Z-0x
 for 68620 <at> debbugs.gnu.org; Tue, 23 Apr 2024 16:21:28 +0000
Message-ID: <8f6868c8a6f535da940abb9c43837601cdd2bfb9.camel@HIDDEN>
Subject: Moved into 68621
From: Dale Mellor <guix-devel-0brg6a@HIDDEN>
To: 68620 <at> debbugs.gnu.org
Date: Tue, 23 Apr 2024 17:21:27 +0100
Organization: DM Bespoke Computer Solutions Ltd
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
User-Agent: Evolution 3.48.4 
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 the administrator of that system for details.
 Content preview:  This patch belongs to issue 68621, closing this one. 
 Content analysis details:   (1.3 points, 10.0 required)
 pts rule name              description
 ---- ---------------------- --------------------------------------------------
 -0.0 SPF_PASS               SPF: sender matches SPF record
 -0.0 SPF_HELO_PASS          SPF: HELO matches SPF record
 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Debbugs-Envelope-To: 68620
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: 0.3 (/)

This patch belongs to issue 68621, closing this one.




Information forwarded to guix-patches@HIDDEN:
bug#68620; Package guix-patches. Full text available.

Message received at submit <at> debbugs.gnu.org:


Received: (at submit) by debbugs.gnu.org; 20 Jan 2024 21:26:37 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Sat Jan 20 16:26:37 2024
Received: from localhost ([127.0.0.1]:35978 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1rRIrM-0008R3-UZ
	for submit <at> debbugs.gnu.org; Sat, 20 Jan 2024 16:26:37 -0500
Received: from lists.gnu.org ([2001:470:142::17]:52588)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <hello@HIDDEN>) id 1rRIrI-0008Qe-9r
 for submit <at> debbugs.gnu.org; Sat, 20 Jan 2024 16:26:35 -0500
Received: from eggs.gnu.org ([2001:470:142:3::10])
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <hello@HIDDEN>) id 1rRIr5-00009t-Mf
 for guix-patches@HIDDEN; Sat, 20 Jan 2024 16:26:21 -0500
Received: from out1-smtp.messagingengine.com ([66.111.4.25])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <hello@HIDDEN>) id 1rRIr4-0000As-30
 for guix-patches@HIDDEN; Sat, 20 Jan 2024 16:26:19 -0500
Received: from compute7.internal (compute7.nyi.internal [10.202.2.48])
 by mailout.nyi.internal (Postfix) with ESMTP id 9E5175C00AB;
 Sat, 20 Jan 2024 16:26:17 -0500 (EST)
Received: from mailfrontend1 ([10.202.2.162])
 by compute7.internal (MEProxy); Sat, 20 Jan 2024 16:26:17 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lnikki.la; h=cc
 :cc:content-transfer-encoding:content-type:date:date:from:from
 :in-reply-to:in-reply-to:message-id:mime-version:references
 :reply-to:subject:subject:to:to; s=fm1; t=1705785977; x=
 1705872377; bh=A1MmHmKukamJyPcTH5lZ0WlxhzewoTJbxKTjUDYfpso=; b=P
 KmXnKG6yhGkKyA6sNgBkNnqLw/kDJkP5WvuFfgvvyqhzCGAHTjYHpUuYlpKD2Elw
 RZzQHoqC31i0MXGsblRtokMFplEwUEr+Td0isabXucGDwQKvDzSRXK91u/6nW+Pm
 DL+AcBcZmOEmIebZ7BdL9s+5YBKSwz92NnRwsY8iJcJism1CvWLGhj2TQ7xlVddU
 hcnvnqOQYlZZh16oOGBgUWrwGOkhXDweRrjdrrzw+FBkjVND7IEimB4XM5hiN27v
 zgdVbIkpZxueZsY9xThu20xwuoxiCIQ6WDxv2NwVophY1uMCRl/e8pTPFwriKE/S
 5dVLhIU+1ZwCjVDSjfIBQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:cc:content-transfer-encoding
 :content-type:date:date:feedback-id:feedback-id:from:from
 :in-reply-to:in-reply-to:message-id:mime-version:references
 :reply-to:subject:subject:to:to:x-me-proxy:x-me-proxy
 :x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t=1705785977; x=
 1705872377; bh=A1MmHmKukamJyPcTH5lZ0WlxhzewoTJbxKTjUDYfpso=; b=s
 Q/ve8h/K/zGBSDnynoKWsePWj9hlOcUCpC4OQKUr9X3oeroiPI8mzdCBS78AxQV0
 ELW2j2/z+cO4vCx5e0ecfao+w+2Ly6hZ566YP3PH1c56+48gqHvDi3Wk2sWzQi6A
 kBUXsRsouevkG/iRL89yJXjl39x6NMIQKYkT44atUNjuVByWCAfYg5R6tZqyey2W
 vfC5cBlAEykx3HOCuHrm+uSmG8Jr3qSoSMpGrNdWFU2OUhYPidzP4YhWmzJJNJOS
 QRBX0p2B1vawf1LzNLQszme53JK2BjfFBnnAPCCIr70YAknbtn2eYPXHNpEMhkll
 nhbchCBkaQryUUWdljcNQ==
X-ME-Sender: <xms:eTqsZSxnU0fGG4UPzCpLNoCUGTt-8HL2gLCWpGsj5AC2l8be2TXHfA>
 <xme:eTqsZeSRutk0LLl6Q50r3ObnWeMnD4CJiTk3JpdUn2XPdlMUOFBM-cAkTPgIfdoG6
 dsePQDVGDhPJTh3XMg>
X-ME-Received: <xmr:eTqsZUVOE4ErItHg_l8gU84UG2lAOhisqL4vLfCpozrOABPRrK5J-lrc2pEdE_BjyjZCjahP1jvSDezPGx1XLgiEHgETWaD-bUY>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvkedrvdekvddgudehtdcutefuodetggdotefrod
 ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh
 necuuegrihhlohhuthemuceftddtnecunecujfgurhephffvvefufffkofgjfhgggfestd
 ekredtredtjeenucfhrhhomhepnfgvohcupfhikhhkihhlmocuoehhvghllhhosehlnhhi
 khhkihdrlhgrqeenucggtffrrghtthgvrhhnpeffkeehheefjeejveejheegvedutefgje
 efvdeihfduffffueeukeeffefhiedufeenucffohhmrghinheplhhurgdrihhnnecuvehl
 uhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhephhgvlhhloheslh
 hnihhkkhhirdhlrg
X-ME-Proxy: <xmx:eTqsZYi9CZCAgz34-3k_RvDkCv6DYx2J5d_9uFFMLWc6hsUEjyn3dw>
 <xmx:eTqsZUCnEfq0XL9LUUdJykkiBPss7V4M8XBOGWkxDXtkIN0X9mmpJw>
 <xmx:eTqsZZJSroUelUXRhlLdY2aff34qz0cv-N0tlsqvAHShLcNtRDxizQ>
 <xmx:eTqsZT44M6vesLahOQatCIHUR72Vx2B1w4eD5UvZONITW6_78oPOEA>
Feedback-ID: i41f146a7:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat,
 20 Jan 2024 16:26:16 -0500 (EST)
From: =?utf-8?Q?Leo=20Nikkil=C3=A4?= <hello@HIDDEN>
To: guix-patches@HIDDEN
Subject: [PATCH 1/2] gnu: knot-resolver: Re-enable default DNSSEC trust
 anchors.
Date: Sat, 20 Jan 2024 23:23:43 +0200
Message-ID: <20240120212542.17473-2-hello@HIDDEN>
X-Mailer: git-send-email 2.41.0
In-Reply-To: <20240120212542.17473-1-hello@HIDDEN>
References: <20240120212542.17473-1-hello@HIDDEN>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Received-SPF: pass client-ip=66.111.4.25; envelope-from=hello@HIDDEN;
 helo=out1-smtp.messagingengine.com
X-Spam_score_int: -27
X-Spam_score: -2.8
X-Spam_bar: --
X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001,
 SPF_HELO_PASS=-0.001, SPF_PASS=-0.001,
 T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: 1.0 (+)
X-Debbugs-Envelope-To: submit
Cc: =?UTF-8?q?Leo=20Nikkil=C3=A4?= <hello@HIDDEN>
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -0.0 (/)

* gnu/packages/dns.scm (knot-resolver) [#:configure-flags]: Configure
root keys and managed TA.
[#:phases] Remove `'disable-default-ta', add `'install-root-keys'.
---
 gnu/packages/dns.scm | 20 +++++++++++++-------
 1 file changed, 13 insertions(+), 7 deletions(-)

diff --git a/gnu/packages/dns.scm b/gnu/packages/dns.scm
index 73a2fac54b..9783e560fa 100644
--- a/gnu/packages/dns.scm
+++ b/gnu/packages/dns.scm
@@ -994,15 +994,13 @@ (define-public knot-resolver
     (build-system meson-build-system)
     (outputs '("out" "doc"))
     (arguments
-     '(#:configure-flags '("-Ddoc=enabled")
+     `(#:configure-flags
+       '("-Ddoc=enabled"
+         "-Dinstall_root_keys=disabled" ; installed manually outside store
+         "-Dkeyfile_default=/var/cache/knot-resolver/root.keys"
+         "-Dmanaged_ta=enabled")
        #:phases
        (modify-phases %standard-phases
-         (add-before 'configure 'disable-default-ta
-           (lambda _
-             ;;  Disable the default managed root TA, since we don't have
-             ;;  write access to the keyfile and its directory in store.
-             (substitute* "daemon/lua/sandbox.lua.in"
-               (("^trust_anchors\\.add_file.*") ""))))
          (add-after 'build 'build-doc
            (lambda _
              (invoke "ninja" "doc")))
@@ -1020,6 +1018,14 @@ (define-public knot-resolver
                 '("doc/knot-resolver/examples"
                   "doc/knot-resolver/html"
                   "info")))))
+         (add-after 'install 'install-root-keys
+           (lambda* (#:key outputs #:allow-other-keys)
+             (let ((dir (string-append (assoc-ref outputs "out")
+                                       "/etc/knot-resolver")))
+               (mkdir-p dir)
+               (install-file (string-append "../knot-resolver-" ,version
+                                            "/etc/root.keys")
+                             dir))))
          (add-after 'install 'wrap-binary
            (lambda* (#:key inputs outputs #:allow-other-keys)
              (let* ((out (assoc-ref outputs "out"))
-- 
2.41.0





Acknowledgement sent to Leo Nikkilä <hello@HIDDEN>:
New bug report received and forwarded. Copy sent to guix-patches@HIDDEN. Full text available.
Report forwarded to guix-patches@HIDDEN:
bug#68620; Package guix-patches. Full text available.
Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.
Last modified: Tue, 23 Apr 2024 18:00:12 UTC

GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997 nCipher Corporation Ltd, 1994-97 Ian Jackson.