head 1.1; access; symbols; locks; strict; comment @# @; 1.1 date 2026.10.06.11.23.17; author drixter; state Exp; branches; next ; commitid Z33nYmIKFAXvnpYG; desc @@ 1.1 log @rcvd: Add version 0.3.1 rcvd is a privacy-first encrypted DNS engine: a single Go binary driven by purpose-built configuration files. It speaks DNS over QUIC (DoQ), DNS over TLS (DoT), and DNS over HTTPS (DoH/DoH3), and never falls back to cleartext DNS. If every encrypted upstream fails it returns SERVFAIL rather than leaking a query over port 53. Features include multi-upstream fallback with health checks, DNSSEC validation, domain blocklists (plain-list and hosts formats, with wildcard support), a local cache, runtime statistics, and both forwarder and DoH-service (upstream) modes. TLS can be automated via ACME (certmagic) so a DoH endpoint presents a real CA certificate with a DNS-ID in its SAN. rcvd: Update to version 0.3.1 Privacy-first DNS. One binary, encrypted egress only This is a small bug fix release. There are no new features and no configuration changes. Fixed: rcvd panicked on shutdown and exited with status 2 instead of 0. This affected every platform whenever a Mode 1 listener was running. Clean shutdown When rcvd received SIGTERM, the server and the main process both closed the upstream resolver chain. The second close panicked. DNS service was not affected while running, but every stop ended in a panic: the exit status was 2, and the final RCVD stopped log line was never written. Service managers notice that. OpenRC and systemd report the stop as a failure, and anything that watches the exit code or the shutdown log line gets the wrong signal. Closing the upstream chain is now idempotent, so a second close is a no-op. A new unit test covers the double close. A shutdown regression check in our container test suite confirms that SIGTERM now exits 0 and logs RCVD stopped. The bug was present since v0.1.0 on all platforms. A Mode 2-only configuration was not affected, because it closes the chain only once. @ text @#!@@RCD_SCRIPTS_SHELL@@ # # $NetBSD$ # # PROVIDE: rcvd # REQUIRE: DAEMON SERVERS # KEYWORD: shutdown # # rcvd: privacy-first encrypted DNS engine. # # The REQUIRE line above matches the pkgsrc convention for a DNS forwarder # (as used by dnsmasq and unbound): rcvd starts in the normal daemon batch. # If you run rcvd AS THE SYSTEM RESOLVER, so that other local daemons resolve # names through it, use the named(8)-style ordering instead so rcvd comes up # first (rcvd bootstraps over pinned IPs, needing no cleartext DNS): # # REQUIRE: NETWORKING # # BEFORE: DAEMON # # To enable, add the following to /etc/rc.conf: # rcvd=YES # # Optional overrides (defaults shown): # rcvd_conf="@@PKG_SYSCONFDIR@@/rcvd/rcvd.toml" # rcvd_user="rcvd" # rcvd_flags="-config ${rcvd_conf}" . /etc/rc.subr name="rcvd" rcvar=${name} command="@@PREFIX@@/bin/rcvd" : ${rcvd_conf:="@@PKG_SYSCONFDIR@@/rcvd/rcvd.toml"} : ${rcvd_user:="rcvd"} : ${rcvd_flags:="-config ${rcvd_conf}"} command_args="&" required_files="${rcvd_conf}" load_rc_config $name run_rc_command "$1" @