head	1.1;
access;
symbols;
locks; strict;
comment	@# @;


1.1
date	2026.10.06.11.23.17;	author drixter;	state Exp;
branches;
next	;
commitid	Z33nYmIKFAXvnpYG;


desc
@@


1.1
log
@rcvd: Add version 0.3.1

rcvd is a privacy-first encrypted DNS engine: a single Go binary driven by
purpose-built configuration files. It speaks DNS over QUIC (DoQ), DNS over
TLS (DoT), and DNS over HTTPS (DoH/DoH3), and never falls back to cleartext
DNS. If every encrypted upstream fails it returns SERVFAIL rather than leaking
a query over port 53.

Features include multi-upstream fallback with health checks, DNSSEC
validation, domain blocklists (plain-list and hosts formats, with wildcard
support), a local cache, runtime statistics, and both forwarder and
DoH-service (upstream) modes. TLS can be automated via ACME (certmagic) so a
DoH endpoint presents a real CA certificate with a DNS-ID in its SAN.

rcvd: Update to version 0.3.1

Privacy-first DNS. One binary, encrypted egress only

This is a small bug fix release. There are no new features and no configuration changes.

Fixed: rcvd panicked on shutdown and exited with status 2 instead of 0. This affected every
platform whenever a Mode 1 listener was running.
Clean shutdown
When rcvd received SIGTERM, the server and the main process both closed the upstream resolver
chain. The second close panicked. DNS service was not affected while running, but every stop ended
in a panic: the exit status was 2, and the final RCVD stopped log line was never written.

Service managers notice that. OpenRC and systemd report the stop as a failure, and anything that
watches the exit code or the shutdown log line gets the wrong signal.

Closing the upstream chain is now idempotent, so a second close is a no-op. A new unit test covers
the double close. A shutdown regression check in our container test suite confirms that SIGTERM
now exits 0 and logs RCVD stopped.

The bug was present since v0.1.0 on all platforms. A Mode 2-only configuration was not affected,
because it closes the chain only once.
@
text
@# $NetBSD$

DISTNAME=	rcvd-0.3.1
CATEGORIES=	net
MASTER_SITES=	${MASTER_SITE_GITHUB:=rcvd-dns/}
GITHUB_PROJECT=	rcvd
GITHUB_TAG=	v${PKGVERSION_NOREV}

MAINTAINER=	drixter@@e-utp.net
HOMEPAGE=	https://rcvd.net/
COMMENT=	Privacy-first encrypted DNS engine (DoQ/DoT/DoH, no cleartext)
LICENSE=	mit

GO_VERSION_REQD=	127

.include "go-modules.mk"
.include "../../mk/bsd.prefs.mk"

RCVD_USER?=		rcvd
RCVD_GROUP?=		rcvd

PKG_GROUPS+=		${RCVD_GROUP}
PKG_USERS+=		${RCVD_USER}:${RCVD_GROUP}
PKG_GECOS.${RCVD_USER}=	rcvd DNS daemon
PKG_HOME.${RCVD_USER}=	/nonexistent
PKG_SHELL.${RCVD_USER}=	${NOLOGIN}
PKG_GROUPS_VARS+=	RCVD_GROUP
PKG_USERS_VARS+=	RCVD_USER

RCD_SCRIPTS=		rcvd

BUILD_DEFS+=		VARBASE RCVD_USER RCVD_GROUP

OWN_DIRS_PERMS+=	${PKG_SYSCONFDIR}/rcvd ${RCVD_USER} ${RCVD_GROUP} 0755
OWN_DIRS_PERMS+=	${VARBASE}/log/rcvd ${RCVD_USER} ${RCVD_GROUP} 0755

# The example forwarder profile becomes the default config on first install.
EGDIR=			${PREFIX}/share/examples/rcvd
CONF_FILES=		${EGDIR}/rcvd.toml ${PKG_SYSCONFDIR}/rcvd/rcvd.toml

# Stamp version, date, and source into the binary (parity with the release
# recipe). buildDate is derived from SOURCE_DATE_EPOCH so the build stays
# reproducible: pkgsrc sets it (to a fixed value) under PKGSRC_MKREPRO=yes;
# otherwise it is unset and buildDate keeps the source default ("unknown"),
# never a varying wall-clock time. The release tarball carries no .git, so
# the commit is "unknown" too, by design.
GO_LDFLAGS=		-s -w \
			-X main.version=${PKGVERSION_NOREV} \
			-X main.buildSource=pkgsrc
.if !empty(SOURCE_DATE_EPOCH)
BUILD_DATE_cmd=		date -u -d "@@${SOURCE_DATE_EPOCH}" +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || \
			date -u -r "${SOURCE_DATE_EPOCH}" +%Y-%m-%dT%H:%M:%SZ
GO_LDFLAGS+=		-X main.buildDate=${BUILD_DATE_cmd:sh}
.endif
GOFLAGS+=		-ldflags=${GO_LDFLAGS:Q}
GO_BUILD_PATTERN=	./cmd/rcvd

# rcvd is a pure-Go static binary (no cgo), matching the upstream release recipe.
MAKE_ENV+=		CGO_ENABLED=0

INSTALLATION_DIRS+=	${EGDIR} share/doc/rcvd/examples ${PKGMANDIR}/man1

post-install:
	${INSTALL_DATA} ${WRKSRC}/etc/mode1-forwarder-3providers.toml \
		${DESTDIR}${EGDIR}/rcvd.toml
.for f in flagship-dualmode mode1-forwarder-3providers mode2-doh-service
	${INSTALL_DATA} ${WRKSRC}/etc/${f}.toml \
		${DESTDIR}${PREFIX}/share/doc/rcvd/examples/${f}.toml
.endfor
	${INSTALL_MAN} ${WRKSRC}/man/rcvd.1 \
		${DESTDIR}${PREFIX}/${PKGMANDIR}/man1/rcvd.1

.include "../../lang/go/go-module.mk"
.include "../../mk/bsd.pkg.mk"
@
