Unbound 1.26 available
-
Is there any chance we can update Unbound to latest 1.26 anytime soon?
-
It didn't include any new security fixes so unlikely it will make it to any releases.
Is there a particular feature or bug fix in that version you are seeking?
-
@jimp There are lots of Bug Fixes and some good additional features. Why would anyone release new versions?
-
If it doesn't fix and bugs people are actively being affected by and it doesn't add any features also implemented in the GUI, then there isn't a benefit to pulling it in prematurely.
We always update packages with new releases, doing so between releases is reserved for critical things like CVEs, security issues, breaking bugs, etc.
Plus 26.07 has already been released and CE 2.9.0 is in the last stages of the release cycle where things are frozen. It's too late to go into these releases.
-
@jimp I stopped counting after 20 fixes. The list is very large.
When it comes to DNS I think people generally would like to be able to update as soon as possible to the latest version.
I guess you are giving me another very convincing point to run Unbound DNS externally to pfsense.
I was for many , many years. Lately I tried running it on pfsense but I am finding, like this comment that be better served to run it in a external way have full control.
Thank you. -
Upgrading just to upgrade is not a smart move in this case.
Yes, people may want to upgrade things as they become available when they are maintaining them on their own but when it comes to a distribution such as pfSense software, if a new version doesn't offer a directly tangible benefit, then the risk that the version might break already working systems is higher than any potential upside gained simply for "staying current".
We do issue upgrades like that when there are security benefits or bug fixes of significant importance.
-
@jimp DNS is an important part of any infrastructure. People will not report bug about DNS to pfsense since Unbound is build and integrated with so many platforms. The argument that nobody has reported issues is no game here.
You need to look at what has been reported with Unbound.
But, by default when there are updates to DNS server from the network Admin side - I will update.
I don't think that updating Unbound would break any things if you use Unbound API and thus its a clean integration. -
Lots of people report issues to us first because they don't know if it's a bug in Unbound or the way it is configured by pfSense. We should always be the first point of contact because of those cases. It's much more rare for a user of pfSense to report things directly upstream to Unbound.
We do review the items in upstream releases like that and consider if they're worth it each time it happens. When it's worth the trade-off, we update.
-
@jimp What I meant in the last post is that many users that do not use pfsense but have other infrastructures with Unbound DNS would not report anything to pfsense team.
Privacy Policy · Cookie Policy