The London Perl and Raku Workshop takes place on 26th Oct 2024. If your company depends on Perl, please consider sponsoring and/or attending.
$Id: Changes 1977 2024-05-02 09:55:06Z willem $                       -*-text-*-

**** 1.45 May 2, 2024

	Resync with IANA DNS Parameters registry.
	Resync with IANA DNSSEC Algorithm Numbers registry.
	Resync with IANA DS Digest Algorithms registry.
	Add support for EDNS CO flag.

Fix #152756
	Net::DNS::Resolver::UNIX creates $ENV{PATH} key if one doesn't exist

**** 1.44 Feb 15, 2024

	Simplify testing of resolver error paths.
	Prevent read beyond end of RDATA in corrupt SVCB RR.

**** 1.43 Jan 26, 2024

	Update addresses in resolver hints.
	Improve accuracy and completeness of dependency metadata.
	Nameserver: hangs on persistent TCP connection (Windows).
	IPSECKEY: leave gateway undefined for gatetype 0.
	Remove remaining support for GOST.

Fix #151240 DoS vulnerability in TCP handling

Fix #151232
	Net::DNS::Resolver::new hangs for 150s on Win32 with no active DNS

Fix #151075
	Bug in Net::DNS::Resolver::Recurse::_referral

Fix #151074
	Deep recursion in Net::DNS::Resolver::Recurse

**** 1.42 Dec 24, 2023

Fix #150695
	Hang in Net::DNS::Nameserver on Windows

**** 1.41 Nov 28, 2023

	Accept inbound Ethernet "Jumbo" UDP packet.
	Facilitate decoding of mDNS/SD packets with compressed RDATA.
	Update to resync with IANA registry.

Fix #150550
	Error trying to use Socket macro SO_REUSEPORT in Windows

**** 1.40 Aug 30, 2023

	Add support for SVCB dohpath and ohttp parameters.
	More robust test of bgbusy() SpamAssassin workaround.

Fix #149456
	t/05-SOA.t test fails in 2038

Fix #149280
	Deep recursion on subroutine "Net::DNS::Resolver::Recurse::_recurse"

**** 1.39 Jun 1, 2023

Fix #148340
	udpsize uninitialized value

**** 1.38 May 9, 2023 Improve robustness of address parsing.
	Deprecate packet->edns->size() method.
	Deprecate rdatastr() historical RR subtype method.
	Major overhaul of pre-installation test scripts.
	Add new t/
	Refactor socket code and control structure in and improve efficiency of zonefile
	data storage and retrieval.

Fix #148274
	Multicast DNS flag breaks Net::DNS::Parameters::classbyval

Fix #148273
	EDNS extended rcode not handled correctly

Fix #147507 peerhost undefined after $sock->accept

**** 1.37 Mar 13, 2023

	Add links to relevant RFCs in package documentation.

Fix #147038
	resolver->axfr( undef ) fails silently

Fix #145944
	Case sensitivity issue with AXFR

**** 1.36 Dec 30, 2022

	Adopt JSON as presentation notation for EDNS options.
	Disallow zero packet->id in outbound packet.
	Remove deprecated 2-argument TSIG->create() method.
	Revise TSIG test scripts and documentation.

**** 1.35 Oct 4, 2022

	Improve SVCB error reporting.

Fix #144328
	accept_reply test fails with matched consecutive "random"
	generated packet->id

Fix #144299
	Spelling errors.

**** 1.34 May 30, 2022

	Improve robustness of EDNS option compose/decompose functions.
	Simplify code in Makefile.PL.

Fix #142426
	Avoid "Useless use of a constant in void context" warning.

**** 1.33 Dec 16, 2021

Fix #137768
	Test t/05-SVCB.t on Perl 5.18.0 fails with deep recursion.

Fix #144136/#132921
	$resolver->send wrongly overwrites RD flag in user's packet.

**** 1.32 Jul 16, 2021

	Text: Offer both Unicode and escaped-ASCII strings.
	Add LICENSE file to comply with Fedora/RedHat announcement.

Fix #136666
	Net::DNS::RR::ZoneFile parser erroneously strips line
	terminators in quoted string forming part of multiline RR.

**** 1.31 May 2, 2021

	Improve implementation of SVCB record.

**** 1.30 Mar 30, 2021

	Simplify parsing of multi-line RRs in zone file.
	Improve robustness of "dry" resolver tests.
	Avoid deep recursion in non-fatal test report.

**** 1.29 Nov 18, 2020

	Include test number in summary of failed non-fatal tests.
	Remove Net::DNS::SEC specific tests.
	Fix faulty test plan in t/08-recurse.t.

**** 1.28 Oct 23, 2020

	Eliminate indirect object syntax.
	Eliminate grep/map <expression>.

**** 1.27 Sep 11, 2020

Fix #133203
	Net::DNS::RR::LOC erroneously strips non default values from
	string representation

**** 1.26 Aug 6, 2020

	Add HTTPS/SVCB packages.

Fix #132921
	EDNS OPT handling

**** 1.25 Jun 26, 2020

	Parsing of TSIG keyfiles made more robust.

**** 1.24 May 27, 2020

	Accept TSIG key generated by BIND tsig-keygen.
	Add Net::DNS::RR::AMTRELAY package.

**** 1.23 Mar 18, 2020

	Deprecate 2-argument form of TSIG create().

Fix #132170
	[Documentation] Problems with TSIG on ddns update.

Fix #131906
	Undefined errorstring/warning when axfr fails

**** 1.22 Feb 13, 2020

Fix #131579
	Parse issue in Net::DNS::RR->token

	Provide rudimentary decode and print for DSO packet.

**** 1.21 Aug 30, 2019

	Fix error report for non-existent or recursive zone file $INCLUDE.
	Emit one deprecation warning on invocation of obsolete method.
	Rework EDNS0 option construction.
	Remove obsolete Net::DNS::RR::DLV package.
	Add Net::DNS::RR::ZONEMD package.

Fix #128901
	background TCP query logic expects to read entire response at once

**** 1.20 Mar 22, 2019

	TSIG MAC representation changed to Base64 (align with BIND).
	Update to resync with IANA registry.
	Refactor resolver test scripts.
	Revise documentation examples to use AAAA instead of A records.

Fix #128081 fails to resolve domain ""

Fix #127307
	Provide a more informative exception report if application code
	has no "use Net::DNS::SEC" declaration but nevertheless attempts
	to invoke the DNSSEC sign or verify features.

**** 1.19 Nov 14, 2018

	Show structure of EDNS options using Perl-like syntax.

Fix #127557
	Net::DNS::Resolver::Base should use 3 args open

Fix #127182
	Incorrect logic can cause DNS search to emit fruitless queries.

**** 1.18 Sep 21, 2018

	Documentation revised to remove ambigous use of "answer" which
	has been used to refer to both the answer section of a packet
	and the entire reply packet received from a nameserver.

Fix #127018
	Net::DNS::ZoneFile->parse() fails if include directory specified.

Fix #127012
	DNS resolution broken when options ndots used in /etc/resolv.conf

**** 1.17 Jul 25, 2018

Fix #125890
	AXFR: 1 record per packet responses.

Fix #125889
	New NSEC3 for empty non-terminal leaves type bitmap undefined.

Fix #125882
	RDATA name compression pointer calculated incorrectly.

**** 1.16 Jul 15, 2018

	New NSEC3 encloser(), nextcloser() and wildcard() instance
	methods return closest encloser, "next closer" and putative
	wildcard names respectively.

	Add new NSEC covers() instance method.

	New NSEC typemap() instance method interrogates type list.

	IO::Socket::INET6 removed from recommended module metadata.
	IPv6 requires IO::Socket::IP which is now a core package.
	No requirement to escape @ in unquoted contiguous string.

**** 1.15 Feb 9, 2018

	GOST R 34.11-94 hash algorithm: end of life 1st Jan 2018
	per sunset clause in successor standard GOST R 34.11-2012.
	Digest::GOST removed from the recommended module metadata,
	but will still be used if available.

**** 1.14 Dec 15, 2017

Fix #123702
	'use base' should not be used in packages with several
	subpackages defined

Fix #123676
	Net::DNS::Nameserver malformed message on big axfr

**** 1.13 Oct 18, 2017

Feature IDN query support
	Queries for domain names containing non-ASCII characters are
	now possible on Unicode platforms using CPAN Net::LibIDN2

**** 1.12 Aug 18, 2017

Fix #122586
	Persistent UDP reports false timeouts

Fix #122352
	bgsend(): TCP retry can stall for IO::Socket::IP before 0.38

	CDS / CDNSKEY: Implement RFC8078 erratum 5049.

**** 1.11 Jun 26, 2017

Fix #122138
	Send a UDP query with udppacketsize=512

	Extract default resolver configuration from OS/390 MVS datasets.
	Thanks to Sandra Carroll and Yaroslav Kuzmin for their assistance.

**** 1.10 May 5, 2017

Fix #120748
	Net::DNS::Resolver::MSWin32 critical issue
	Thanks to Dmytro Zagashev for his valuable assistance during
	the investigation which exposed five distinct issues.

Feature #18819
	Perl 5.22.0 puts EBCDIC character encoding back on the agenda.
	Thanks to Yaroslav Kuzmin for successful test build on os390.

**** 1.09 March 24, 2017

Fix #120542
	Fails tests when no "." in @INC

Fix #120470
	Fragmented TCP length not correctly reassembled

Feature #75357
	Add mechanism to encode/decode EDNS option octet strings

**** 1.08 February 20, 2017

	Discontinue support for pre-5.6 perl
	Remove pre-5.6 workarounds and outdated language features

Fix #120208
	Unable to install 1.07 in local::lib environment

Feature #119679
	Net::DNS::Nameserver: UpdateHandler for responding to UPDATE packets

Feature #75357
	Net::DNS::Nameserver: optionmask (similar to headermask) added
	to allow user to set EDNS options in reply packet

**** 1.07 December 29, 2016

Fix #118598/#108908
	Serious Makefile.PL issues
	"make install" now suppressed if pre-1.01 version detected

Fix #115558
	Net::DNS::Nameserver does not allow EDNS replies

Fix #114917
	Net::DNS::ZoneFile fails to parse mixed case mnemonics

Fix #114876
	Use of uninitialized value in lc at line 77

Fix #114819
	Net::DNS fails to compile with taint checks enabled

	Add support for dynamic RR subtype package creation
	per draft-levine-dnsextlang

**** 1.06 May 27, 2016

Fix #114918
	Net::DNS::ZoneFile fails when unnamed RR follows $ORIGIN

Fix #114351
	Case sensitive compression breaks resolver->nameservers()

Fix #113579
	Net::DNS::Resolver dies on scoped IPv6 nameserver address

Fix #113020
	Resolve::Recurse Hangs

Fix #112860
	improperly terminated AXFR at t/08-IPv4.t line 446.

**** 1.05 March 7, 2016

Fix #111559
	1.04: TSIG not working anymore (

Fix #108908
	Installing recent version gets shadowed by old version.
	Warnings added to Makefile.PL and t/00-version.t.

Fix #66900
	Net::DNS::Async unable to retry truncated UDP using TCP because
	of limitations in Net::DNS.

**** 1.04 December 8, 2015

Fix #109183
	Semantics of "retry" and "retrans" options has changed with 1.03

Fix #109152
	Deprecated method make_query_packet breaks calling code

Fix #109135
	Resolver behaves differently with long and short IPv6 address format

Fix #108745
	Net::DNS::Resolver bgsend

**** 1.03 November 6, 2015

Fix #107897
	t/10-recurse.t freezes, never completes

Fix #101978
	Update Net::DNS to use IO::Socket::IP

Fix #84375
	Timeout doesn't work with bgsend/bgread

Fix #47050
	persistent sockets for Resolver::bg(send|read|isready)

Fix #15515
	bgsend on TCP

**** 1.02 September 16, 2015

Fix #107052
 	suppress messages: Can't locate Net/DNS/Resolver/

Fix #106916
	Dependency on MIME::Base32 makes Net::DNS not installable on MSWin32

Fix #106565
	Net::DNS::Resolver::Recurse and IPv6 Reverse DNS

Fix #105808
	Version test for Pod::Test is broken

**** 1.01 Jul 6, 2015

	The RRs previously only available with Net::DNS::SEC are now
	integrated with Net::DNS.  Net::DNS::SEC needs to be installed
	to enable the signature generation and verification functions.

Fix #105491
	Can't call method "zclass" on an undefined value at ... Net/DNS/ line 474

Fix #105421
	Dead link in Net::DNS::FAQ

Fix #104657
	Wrong split on Cygwin

Fix #102810
	Dynamic update: rr_add overrides ttl of zero

Fix #102809
	CAA broken

**** 0.83 Feb 26, 2015

Fix #101798

	AUTOLOAD error confusing w/o reference to object class

Fix #101709

	Provide separate control of IPv6 tests

Fix #101675

	MX record with 0 preference fails to parse

Fix #101405

	Install tests fail for v0.81 on Perl 5.21.7

**** 0.82 Jan 20, 2015

Fix #100385

	Support for IPv6 link-local addresses with scope_id

**** 0.81 Oct 29, 2014

Fix #99571

	AXFR BADSIG failures

Fix #99531

	Resolver doc error - when is a 'bug' a 'bug'? [TSIG verification]

Fix #99528

	TSIG::create fails with some filenames
Fix #99527

	Random errors... [declaration with statement modifier]

Fix #99429

	Infinite recursion in Net::DNS::Resolver::Recurse::send when
	following certain delegations with empty non-terminals.

Fix #99320

	Net::DNS::ZoneFile bug in "$ORIGIN ."

**** 0.80 Sep 22, 2014

Removal of Win32::IPHelper support with cygwin

	Resolvers on Cygwin can get their DNS configuration from the
	registry directly via the /proc filesystem.  Getting rid of
	the other method reduces dependencies and makes installations
	less error prone.

Rework #96119

	"Too late to run INIT block" warning for require Net::DNS

**** 0.79 Aug 22, 2014

Feature #98149

	Add support for Android platform.

Fix #97736

	Net::DNS::Resolver->new mistakenly copies supplied arguments
	into default configuration on first instantiation.

Fix #97502

	Net::DNS::Resolver->retrans does not accept a value of 1 (uses 2 instead)

Fix #83642

	Configure CD flag in Net::DNS::Resolver->new

Fix #81760

	Reverted workaround for TXT issue preventing propagation of
	rule updates for SpamAssassin versions earlier than 3.4.0

Fix #16630

	Net::DNS::Resolver::Recurse issues lots of IMHO unnecessary DNS requests.

**** 0.78 Jul 10, 2014

Fix #97036

	Nameserver identification on Cygwin

Fix #96814

	Trailing comments not stripped in /etc/resolv.conf

Fix #96812

	Net::DNS::Resolver->new() hangs if nameserver :: exists

Fix #96755

	RFC 3597 (hex) parsing mistake

Fix #96708

	String treated as boolean in TXT

Fix #96608

	"Insecure dependency in connect" with Net::DNS::Resolver over TCP

Fix #96535

	Net::DNS::Resolver warns "Use of uninitialized value in length"

Fix #96531

	Calling $resolver->nameservers multiple times returns an
	increasingly-long list (on some perl installations)

Fix #96439

	Uninitialised decoding object when printing packet

**** 0.77 Jun 13, 2014

Fix #96151

	Unlocalised $_ modified when reading config file

Fix #96135

	Deep recursion problem on Cygwin

Fix #96119

	"Too late to run INIT block" warning for require Net::DNS
Fix #96035
	Insert missing plan 'no-plan' in 10-recurse.t

Fix inefficient Net::DNS::SEC compatibility code

**** 0.76 May 23, 2014

Fix #95738

	Test failure with IPv6 address in resolver.conf but without
	prerequisite IO::Socket::INET6 package installed.

Fix #95596

	Incorrect parsing of nameserver lines in resolv.conf

Feature #79568

	Implement prefer_v6 resolver configuration attribute.

Fix #67602

	Set resolver configuration defaults at first instantiation
	instead of module load time.

**** 0.75 May 8, 2014

Fix #94069

	Compile-time constant in cannot be used to
	store pointer to encoding object when using perlcc compiler.
	Thanks are due to Reini Urban for testing the revised code.

Fix #93764

	Resolver gives unhelpful errorstring when attempting to use
	IPv6-only nameserver without INET6 and Socket6 installed.

Fix #92626

	Clarify documentation surrounding SRV RR sorting


	Implement TSIG verified zone transfer.

Fix #92433 & #91241

	TSIG: implement sign/verify for multi-packet message.

Fix #79569

	Iterate nameservers in AXFR

**** 0.74 Jan 16, 2014

Fix #91306

	Nameserver crashes on malformed UDP query.

Fix #91241

	TSIG: Fix incorrectly generated %algbyval table.


	Add CAA, EUI48 and EUI64 RR implementation.

**** 0.73 Nov 29, 2013

Fix #88778

	$update->unique_push() does not work as advertised.

Fix #88744

	Nameserver crashes on malformed TCP query.

Fix #84601/#81942

	Fix memory leak on packet cleanup. Indirect self-reference via
	header prevented garbage collector from deallocating packet.

Feature #84468

	TSIG: add support for HMAC-SHA1 .. HMAC-SHA512

Fix #84110

	Incorrect parsing of PTR records in zonefile.

Fix #83755

	Erroneous attempt to invoke Net::LibIDN package in

Fix #83078

	Can't locate Net/DNS/Resolver/ in @INC
	Conjecture:  eval{ ... };  if ($@) { ... };  broken by threads.

Fix #83075 wrongly rejects $TTL 0 directive.

Fix #82621

	Error string empty after failed TCP query.

Fix #82296

	IPv6 with embedded IPv4 address not mapped to

Fix #82294

	Perl taint inadvertently removed in Domain and Text objects.

Feature #53610

	add TSIG validation support

**** 0.72 Dec 28, 2012

Fix #82148

	nxrrset fails to ignore RDATA.

Fix #82134

	TSIG key and algorithm names not downcased in digest.
	Class not forced to ANY.

Fix #82063

	yxrrset, nxrrset and rr_del functions should force zero TTL.

Fix #82047
	Clarify documentation to indicate that header counts may
	differ from the number of RRs present if a packet is corrupt.

Fix #81941

	Clarify documentation to make users aware that bgread will not
	switch to TCP when a truncated packet is received.

**** 0.71 Dec 15, 2012

Temporary workaround #81760

	The rdatastr method for TXT RRs will return unconditionally 
	quoted rdata fields to work around an issue with updating 
	SpamAssassin rules.  This workaround will be reverted after
	release of a version of SpamAssassin which resolves the issue.

Fix TSIG initialization

	Uninitialised algorithm attribute caused signature generation
	to fail silently when creating a TSIG signed packet.

Fix #81869
	The rr_del auxiliary function broken by a conflicting change
	in the string parser. Note the ambiguous use of ANY,
	which may stand for CLASS255 or TYPE255 depending upon the
	argument string presented.

Fix #81756

	Test failures on Perl 5.8.5 .. 5.8.8.
	lc(), uc() and case insensitive regex matching broken for UTF8.
	Thanks are due to Paul Howarth for patient work with perl -d.
Fix #81787

	NXDOMAIN no longer reported by $resolver->errorstring.

Fix #81814

	Allow zero in format, tag and algorithm fields of CERT RR.

Fix #81786

	Substitute last owner for leading spaces in multiline zonefile RR.

Fix #77444

	Make use of new extended header modus operandi for OPT records
	also in the resolver. Preventing a warning.

**** 0.70 Dec 6, 2012

	Add support for NID L32 L64 LP, RFC6742.

**** 0.69 Dec 5, 2012

Feature #62030

	Parsing of BIND zone files implemented in Net::DNS::ZoneFile.
	This replaces and is backward compatible with the CPAN module
	of the same name.

Enhancement to simplify RR subtype template and recode packages.

Enhancement #75185

	Packet decoder returns index to end of decoded data.

	Added packet->reply() method.

Fix #79569

	AXFR not setting packet->answer_from.

Enhancement #18819

	Added support for Unicode and non-ASCII character encoding.

Feature integrate OPT as a header extension

	Treat extended rcodes and the DO flag like they are part of
	the packet header.

Fix #77444

	Support escaped characters according to RFC1035 in TXT rdata.

Fix #77304

	Fix resolver searchlist from registry setup on Win32.

Enhancement #67570

	Make wire2presentation two till eighteen times faster.
	A contribution from Matthew Horsfall

Fix #73366

	Remove existing TSIG when resigning with a new TSIG and give warning.

Fix #75330

	Also try nameserver without glue (as a last resort) when recursing.

Fix #74493

	Read correct resolver configuration in OS/2.

**** 0.68 Jan 30, 2012

Fix #72314
	Let a Net::DNS::Nameserver bind on Net::DNS::Nameserver::DEFAULT_ADDR
	as a last resort.

Fix to suppress false warnings about subroutine profiles on ancient
	versions of perl.

Fix to avoid constants with value undef which prevents unwanted code from being
	optimized away on ancient versions of perl.

Fix code error in, canonical RDATA not downcased.

Enhancement to clarify the function of parse and data methods, by renaming them
	to decode and encode respectively.

Feature IDN query support. modified to use the recently introduced
	module to represent DNS names.  Queries for domain names containing
	non-ASCII characters are now possible on Unicode platforms with CPAN 
	Net::LibIDN installed.

Introduction of module that will be used in the future to represent 
	RDATA components containing DNS coded RFC822 mailbox addresses.

Introduction of module that will be used in the future to represent
	RDATA components containing text.

**** 0.67 Nov 4, 2011

Enhancement #60726

        On Cygwin Net::DNS now builds without Win32::IPHelper, unless a 
        previous version is updated that did use it. 
        The choice may also be set by the --iphelper or --noiphelper option
        to Makefile.PL.

Fix to suppress IO::Socket::INET(6)::peerhost usage with TCP. On some systems
        it doesn't work after receiving data.

Enhancement #43142

        Allow ReplyHandlers to indicate that no answer should be returned
        by the Net::DNS::Nameserver.

Fix #71796

	Prevent TCP accepts from blocking on unfinished 3-way handshakes.

Fix #65607

	Make 64bits windows work by depending on Win32::IPHelper version 0.07
	Thanks to Lian Wan Situ.

Fix #66470

	Named nameserver should be reachable by IPv6 too.

Fix to make tests work in jailed environments where a reply might come
	from a different address than that of the loopback interface.

Feature to use a class method ReplyHandler for classes inheriting from

	A contribution from Rob Brown.

Fix #71062

	Replace the usage of the obsolete Win32::Registry module by
	Win32::TieRegistry module.

Fix #68731

	Fix linking of the C compiled parts of the library on Mac OS X

New improved version of the check_soa script in the contrib section.
	A contribution from Dick Franks.

Fix #70830

	Make t/08-online.t handle NXDOMAIN hijacking that return more than one

Fix #24525

	Removed dependency on Net::IP

Fix online tests to use the library as documented and not use knowledge of the
	internal workings of the classes that should be hidden.

	A contribution from Dick Franks

Fix #55682
	Make online tests non-fatal by default.
	All interactive prompts are removed from Makefile.PL.
	Online tests may still be made a requisite by using the --online-tests
Major rework of and the addition of

	Which paves the way towards handling of character encodings and IDN.
	A contribution from Dick Franks.
Fix #69174

	Typo that prevented TCP traffic from being replied from the same
	socket as it was received on.

Fix #68338

	Suppress warnings of the deprecated use of qw as parentheses in 
	perl 5.14.

Enhancement #67418

	A contribution from Wolfsage to perform presentation to wire format
	conversion more efficiently.

Fix #67133

	Gracefully handle corrupted incoming packets in Net::DNS::Nameserver.

Feature to manage serial numbers in SOA records in a modular and extensible way.

	Three modules are provided. Strictly sequential, Date Encoded and 
	Time Encoded.  A contribution from Dick Franks.

Fix #53325

	Make Net::DNS::Resolver load even if /etc/resolv.conf is unreadable.

Fix #63486

	Make t/08-online.t fail gracefully in stead of crash on failures.

Fix #55586

	Various typo fixes.

Fix #55682

	Really do not use networking functions when online tests are disabled.

Fix #64562
	Replace TSIG key with the signature of the whole packet when signing
	a packet, even when the TSIG key is not the first in the additional 

Fix #56181 and #47265

	Assembly of segmented TCP traffic.

Feature #57289

	Provide a configurable IdleTimeout for Net::DNS::Namserver.

Fix #53595

	Fix documentation to reflect code behaviour where on successful packet
	creation, the error should be ignored.

Fix #58914

	Fix spelling of "algorithm"

Fix #61725

	Include default domain in the search list on Win32.
	Thanks Mark Rallen.

Fix #63321

	A Net::DNS::Nameserver without a NotifyHandler now responds NOTIMP
 	to NOTIFY requests.

Fix #53595
	Documentation now reflects Net::DNS::Packet construction behaviour.

**** 0.66 Dec 30, 2009

Feature Truncation for Nameserver
    fixes #33547 and #42744

    this feature may cause unexpected behavior for your nameservers
    and can be turned off by setting Truncate to 0 during the creation
    of the nameserver. 
    my $ns = Net::DNS::Nameserver->new(
		Truncate => 0,


    Net::DNS::Packet::truncate is a new method that is called from
    within Net::DNS::Nameserver that truncates a packet according to
    the rules of RFC2181 section 9.

    Acknowledgement Aaron Crane for an elegant test and for
    inspiration for a direction.

Feature: Added Net::DNS::Domain
    Net::DNS::Domain is an attempt to introduce a consistent model
    for representation of RFC 1035 <domain-name>s.

    The class and its test script t/02-domain.t are included to be
    exposed to various architectures.

    The class and its methods may be subject to change, both in terms of
    naming and functionality.
    A contribution by Dick Franks

Fix improved fuzzy matching of CLASS and TYPE in the Question
    constructor method.

    A contribution by Dick Franks.

Fix #43770

    Update->rr_del() was reported broken for AAAA after 0.65.
    The same bug also occurred in HINFO RR.

Fix #43765
    Code inconsistent with documentation for loop_once.

    Note: Keeping timeout undefined in loop_once will now block until
    something arrived on the socket.

Fix #47050

    Fixed logic error in bgsend socket acquisition code.

Fix #47265 (partial)

    Frequently Net:DNS under Windows XP has a UDP problem which is
    caused by a buggy implementation of SOCKS under Windows.

    One liner added to not continue UDP processing when that happens.

Feature KX RR
    Added support for the KX RR, RFC2230
    The implementation is trivial since the KX inherits almost all of
    its functionality by inheritance from the MX RR.

Fix NSAP RR string representation

    RFC1706 specifies the masterfile format to have a leading "0x" and
    optional dot. This was not how the RR was represented with the
    rdatastr method (and hence string and print).

Fix #52307 AAAA v4compat parsing bug 
    Acknowledgement: BLBLACK

Fix AAAA dynamic update

    Dynamic update of AAAA caused FORMERR on the prerequisite caused
    by AAAA creating rdata even when an address was never specified.
    This fix may cause difference in behavior for people who expect
    a NULL address ("::") when creating a AAAA without an address

Feature HIP RR

    Added support for the HIP RR, RFC5205
    perldoc Net::DNS::RR::HIP for more information.

Feature DHCID RR
    Added rudimentary support for the DHCID RR.

Fix #50883
    This is basically #11931 but for cygwin.

    Codepath in Cygwin and Win32 are now the same. This adds a
    dependency in cygwin.
    Acknowledgements "mikaraento"

Fix #45407 and #43190
    Fixed escaping of semicolon.

    Note a change in behavior: 
    For TXT and SPF the rdatastr method (and therefore the
    print, and string method) returns the escaped format while the 
    chr_str_list method will return unescaped format.

Fix #43393
    Typo in 01-resolver.t

Fix #43273
    Added check for uninitialized opcode in headermask in

Fix #46635
    Minor documentation error in

Fix #51009
     Fixed handling of empty string in Net::DNS::stripdot. 
     Elegant one-liner supplied by JMEHNLE.

Fix #49035

    Comment parsing fixed: Semicolon in character string blocks (such
    as in TXT and NAPTR) were only recognized when escaped.
    Also fixed the NAPTR regular expression to not interpret 
    "bla' 'foo" as two strings bla and foo, but as one: bla' 'foo

Fix cd flag settings 

    Resolver bug and fix reported by Jon Haidu.

**** 0.65 January 26, 2009

Fix #41076

    When the AAAA object was constructed with new_from_hash with an
    address containing the "::" shorthand notation normalization was
    not done properly.

Fix #42375

    Typo in Registry root.

**** 0.64 December 30, 2008

Feature #36656

    Added support for the APL record (RFC 3123)
    The module consists of a list of Address Prefix Item objects
    as defined in the Net::DNS::RR::APL::ApItem class.
    NOTE: Class and its interface may be subject to change.

Fix #11931 Wrong nameserver list handling in

    The init method has been rewritten to be based on WIN32::IPhelper for
    the selection of the domain and the IP addresses. This is believed to 
    be more portable than trying to fetch the data from the registry.
    We still trying to get the searchlist from the registry.

    WARNING: If you use Perl under WIN32 (eg ActivePerl or Strawberry Perl)
    then your module dependency graph has changed drastically

Fix IPv6 modules
    When IO::Socket::INET6 was available but Socket6 was not the code would
    recurse to infinity.

Fix #21757 and Feature: Connectivity during test
    Addition of --no-IPv6-tests and --IPv6-tests option in Makefile.PL.
    Note: This causes two questions to be asked when building the
    Makefile instead of one.

    Besides the test suites are constructed so that all the connectivity testing
    happen in 001-connectivity.t and nonavailability of connectivity over a certain
    transport is signaled over files t/online.disabled and t/IPv6.disabled respectively.
    Both files are removed by t/99-cleanup

Fix #34511
    Priming query logic contained unneeded recursion. 
    Now also falls back to hardcoded hints if there are no nameservers whatsoever.

Fix #38390 and 37089
    Added CD and AD bit control to the resolver.

    The CD flag defaults to being unset and the AD flags is set by default
    whenever DNSSEC is available. 
    Both flags default to unset in absence of DNSSEC.

Fix #37282
   Improved error reporting during client disconnect from the nameserver

NOTE # 40249

   Release 0.62 introduced a feature to parse data inside a packet only 
   when needed. This can cause the following to happen:

   Exception: corrupt or incomplete data at
                     /usr/lib/perl5/Net/DNS/ line 510.  
   caught at -e line 1

   This may happen when you have undefined your packet data before all the
   sections have been fully parsed. Such as in:

   $packet = Net::DNS::Packet->new(\$data);

   The workaround is to force parsing by calling the methods that 
   parse the data. e.g.

   $packet = Net::DNS::Packet->new(\$data);
   $packet->answer; $packet->additional; $packet->authority;
   undef ($data) 

Fix # 41076 and # 41071

  Net::DNS::RR->new_from_hash function would not normalize the content
  of the data so that a method getting a string representation would
  get inconsistent results depending on whether a RR was created from
  a string of from a hash. 

Fix # 41296

  Compression buggy for large packets. Fix by Kim Minh.

Fix # 35752

  Perl 5.10.0 gave a number of issues on several platforms, preferring
  XSLoader over Dynaloader seemed to fix those.

Bug #34510
  Buggy setting of "Recursion too deep, aborted" corrected.
Feature ( #39284)

  The ReplyHandler now also receives a variable with an anonymous hash with the connection details. Variables
  supplied to the Reply handler are:  $qname, $qclass, $qtype, $peerhost, $query, $conn	
  The hash referenced by $conn contains the following buckets: sockhost, sockport,  peerhost, and peerport.

Feature t/08-online.t and t/10-recurse.t

  In particular environments a query for a.t. will resolve and or
  middleboxes will replace DNS packet content for queries to the root.
  A bunch of test is skipped when this (broken) environment is

Feature/Bug #22019 

  The initial fix for rt 22019 was to strip a trailing dot from all
  attributes that were provided as argument for the
  Net::DNS::RR::new_from_hash function.  We have introduced
  Net::DNS::stripdot, a function that will strip the dots of domain
  names, taking into account possible escapes (e.g. labels like
  foo\\\..).  As a side effect the new_from_string method will now
  convert possible spaces that are not trapped by some of the
  new_from_string functions and convert them to \032 escapes.

  For information: The internal storage of domain names is using
  presentation format without trailing dots. 

  @EXPORT and @EXPORT_OK moved to a BEGIN block so that Net::DNS::SEC 
  can make use of exported functions


  The Notify handler introduced in 0.63 did not set the OPCODE on the
  reply appropriately. This has been solved generically by allowing the
  "Headermask" that is returned as 4th element by the reply or notify
  handler in the nameserver also allows for the opcode to be set.
  e.g. as in return ("NXDOMAIN",[],[],[],{ opcode => "NS_NOTIFY_OP" }

*** 0.63, 8 Feb 2008

This version contains a Security Fix.

Feature NotifyHandler in Nameserver
  The NotifyHandler is a new attribute to the nameserver used in the
  same way as the ReplyHandler except that it is executed when the
  opcode is NS_NOTIFY (RFC1996). It takes the same arguments as the
  reply handler (i.e. $qname, $qclass, $qtype, $peerhost, and $query).
  Corrections made in the documentation.

Fix #32937: 5.11 introduces new warning on uc(undef)

  The patch supplied fixes for methods where undefined arguments were
  likely. For methods where undefined arguments don't make the warning
  will be printed.

Fix #32147: Default LocalAddr broken in Net::DNS::Nameserver 0.62

  Listen on the default address if LocalAddr not defined.

Fix #30316  Security issue with Net::DNS Resolver.

  Net/DNS/RR/ in Net::DNS 0.60 build 654 allows remote attackers
  to cause a denial of service (program "croak") via a crafted DNS
  response ( Packet
  parsing routines are now enclosed in eval blocks to trap exception
  and avoid premature termination of user program.

Bug: mbox-dname and txt-dname were not allowed to be empty in the RP RR.
   Fix by Peter Koch

*** 0.62, 28 December 2007

Features: Move of some functionality out of the Packet to the Question
   and RR classes; parsing of elements in the packet is now performed
   by calling the appropriate subclasses.

   New methods were introduced:
   * Net::DNS::Packet->parse()
   * Net::DNS::RR->parse()
   * Net::DNS::Question->parse()

   The Packet class now defers parsing of authority/additional until
   their content is really needed. This should cause a bit of
   performance improvement.

   Dick Franks is acknowledged for this Good Work (TM).

   Added 20081216 see NOTE above under # 40249

Feature: the Net::DNS::Packet's answersize() method will from now on
    ignore its arguments and just return the size of the packet.

Feature: The Net::DNS::RR->new() method used to call
    Net::DNS::RR->new_from_data() whenever called with the appropriate
    combination of arguments. That (undocumented) behavior has been deprecated.
    Use Net::DNS::RR->new_from_data() directly if you depended on that.

Feature: Net::DNS::Packets unique_push now ignores the TTL in
    comparison of uniqueness, this is closer to the intent of
    RFC2181, but not yet fully compliant.

Fix #29816
    Acquiring the IP address for the Resolver under Cygwin is made
    more resilient.

Fix #31425
    Empty question section in search method detected

Fix #31042
    Makefile corrected to add a library target.

Fix #29818
    10-recurse.t used to fail in very specific environment (where a query for
    qname="." and qtype="NS" would return with an empty additional section).
    Fixed by adding the hints explicitly; this also forces the tests to take
    place under the root served by

Fix #29877
    Made 00-version.t recognize a "GIT" environment.

Fix #29878 did not evaluate as true. Thanks Bjorn Hansen.

Fix #21398
   answersize() and answerfrom() set for persistent sockets

Fix #29883
   Fix various tests only available through SVN, so they are 
   more robust (Acknowledgements Bjoern Hansen)

Fix #24343
   Resolver's nameserver() method would do silly things with undefined 

Fix #29531, and modified to avoid erroneous PTR
   lookup in response to mischievous query packet containing an IP address.

Fix #27970 better netdns.o

    Marek Rouchal provided two minor improvements for linking the C
    code snippets

Fix rt.cpan 28345

    A fix in Test::Simple revealed an off by 1 error in the testplan
    for 05-rr-rrsort.t. The fix is to remove a test, creating a dependency
    on Test::Simple 0.71 seemed overkill.

*** 0.61, 1 August 2007

Fix #28106, 28198, and 28590
    Modification of $_ in various places.  

    t/11-inet6 assumed lowercase domain names.

*** 0.60 20 June 2007

Fix spelling mistakes in change log using interactive spell checker (aspell).

    Two redundant calls of $self->rdatastr() in Net::DNS::RR::string().

Fix #27285 bis
    Unreleased 0.59_1 dn_expand_PP() has security flaw allowing access to
    arbitrary data using crafted packet with out of range compression pointer.
    Patch by Dick Franks based on 0.59 code. 

Fix #27391
    dn_compress() produces corrupt packet for name containing empty label.

Fix #26957
    dn_compress() croaks for name having label which exceeds 63 characters.
    Patch by Dick Franks truncates offending label.

Feature check_soa test of NCACHE TTL
    Dick Franks supplied an improved version of check_soa script which
    performs a direct test of NCACHE TTL by looking up non-existent name and
    reporting value if it exceeds 86400. Test is skipped unless minimumTTL is
    above same threshold.  Recent BIND implementations impose a ceiling on
    NCACHE TTLs internally, so a large minimumTTL value is unlikely to have
    damaging consequences at many sites.

Fix #27285
    Break out of malformed packets with compression loops.
    Steffen Ullrich is acknowledged for patch and test code.

Feature check_zone "alternate domain" and "exception file" flags
    Paul Archer supplied a patch for check_zone adding two new features.

Feature Support for IPSECKEY RR
    Rudimentary IPSECKEY RR support added.

Fix  #25342
    HINFO would only accept its data fields within quotes. That has now
    been fixed to adhere to <character-string> by inheriting parsing functions
    from TXT.

Fix #24631 / Feature IP address prefix notation
    Dick Franks supplied a cleaned up version of

    Revised code deals with incomplete IPv6 address bug and accepts RFC4291
    address prefix notation. IPv4/prefix also supported for completeness.

    This involved a minor change to the API for reverse IP lookup.  Changing
    qtype to PTR is now performed for A and AAAA only.  This allows queries
    for NS and SOA records at interior nodes to be specified using the address
    prefix.  Type ANY queries now also produce the expected result.

    Cleaned up TYPE/CLASS reversal code, exploiting fact that the intersection
    of the sets of class and type names contains only one member (ANY).

    Minor cleanup of remaining code.

Fix #22019

    Expunge trailing dots from RR->new_from_hash() FQDN arguments.
    Patch by Dick Franks.

Fix Recursion and EDNS OPT record

    The Recursive resolver process would add an OPT-RR with each recursion
    which causes FORMERRs with a number of authoritative servers.

Feature SSHFP warn instead of die

    We do not die if a not implemented fingerprint type value is read
    from the wire, instead we 'warn' and return undef.

Feature NSEC3PARAM hook 

    A hook to load NSEC3PARAM when available has been added.
    WARNING: Both NSEC3 and NSEC3PARAM are configured with their
    experimental type codes.

Feature rt r24525 

    Net::DNS::Resolver depended on Net::IP (2268 Kb) which depends on
    heavy module Math::BigInt (1780 Kb). Valery Studennikov suggested to
    ship Net::DNS::Resolver::Base with its own copies of ip_is_ipv[4|6] and
    supplied a patch with those functions stripped from Net::IP.

    Note that the package still depends on Net::IP because
    Net::DNS::Nameserver and a few tests depend on it.

Fix rt 22334
    Fixed "perl Makefile.PL --xs" behavior, patch by Tamas Palfalvi

Fix rt 21752 and 24042
    Applied the patch supplied by Alexandr Ciornii to be able
    to compile on ActiveState perl .
    Slight modifications based on comments by nimnul

Fix rt 23961
    Randomized the ID on the queries. Thanks to "hjp" for reporting and
    suggesting a fix.

    The randomization of the src port is supposed to be handled by the
    setting the source port to "0" (default). Overriding the default
    or using persistent sockets may be problematic.

    Also see:

    Minor compile time warnings for netdns.c on Fedora Core.

*** 0.59 September 18, 2006

Fix 20836, 20857, 20994, and 21402

    These tickets all revolved around proper reverse mapping of IPv6

    Acknowledgments to Dick Franks who has provided elegant solutions and
    cleaned a bit of code.

    Note that directly calling Question->new() without arguments will
    cause the qclass,qtype to be IN, A instead of ANY, ANY.

    Net::DNS::Resolver's search() method would always gracefully
    interpret a qname in the form of an IPv4 address. It would go out
    and do a PTR query in the reverse address tree. This behavior has
    also been applied to IPv6 addresses in their many shapes and

    This change did two things, 1) root zone not implicitly added to
    search list when looking up short name, 2) default domain appended
    to short name if DEFNAMES and not DNSRCH.

Fix 18113

   Minor error due to unapplied part of patch fixed.

Feature: Experimental NSEC3 hooks. 

   Added hook for future support of (experimental) NSEC3 support
   (NSEC3 having an experimental type code).

*** 0.58 July 4, 2006

Feature: hooks for DLV support in Net::DNS::SEC

   added hooks for DLV support which is/will be available in
   Net::DNS::SEC as of subversion version 592 (Tests are done against
   the subversion number, not against the perl release version)
   Net::DNS::SEC version 0.15 will have DLV support.

Partly Fixed 18940

   djhale noticed a number of error conditions under which the
   udp_connection in Nameserver dies. We now print a warning instead
   of dying.

Fix 18958

   Fixed typebyname croak for SIGZERO. Acknowledgments to djhale.

Optimize 11931

   Hanno Stock optimized the method to get the list of available
   interfaces in Win32.  I have only done very rudimentary tests on
   my Windows XP system.

Fix dependency on "CC" 19352

   The Makefile.PL depended on availability of "cc" and would bail
   out on systems where gcc is exclusively available. Thanks to Rob
   Windsor for noticing and patching.

Fix compressed dnames in NAPTR/SRV

    Clayton O'Neill noted that the domain names in the NAPTR and
    SRV RRs rdata were subject to name compression which does not
    conform to specs. Also see RFC 2782 and 2915.

Fix 18897

   Zero-length rdata in TXT fixed (Acknowledgments to Roy Arends)

Fix 18785

   SPF would not work unless the TXT RR was already loaded.
   SPF fully inherits TXT and loading of is therefore a

Fix 18713

    Net::DNS::Resolver now deals gracefully with persistent sockets
    that got disconnected. It will first try to connect again to the
    socket and if that fails it will try to connect to the next
    available nameserver. tcp_timeout() is the parameter that
    determines how long to wait during a reconnect.

Fix 18268

     Added reference to RFC in croak message for label length > 63 in

Fix  18113

    The inet6 tests contained another bug when online-tests were disabled.
    Klaus Heinz discovered and provided a patch.

*** 0.57 February 24, 2006

Fix 17783

    The inet6 tests do not skip enough tests when ipv6 is not available.
    I did not catch this in my setup since IPv6 is available on all my

    Since this breaks automatic CPAN installs a new release is

*** 0.56 February 20, 2006

Fix 17694
   Net::DNS::typesbyval() now confesses on undefined
   args. Acknowledgments to Dean Serenevy.

Feature Implemented SPF (typecode 99).

   The class completely inherits from Net::DNS::RR::TXT (the easiest 
   RR to implement ever).

Feature added rrsort() function.
   Feature was requested by Eric Hall in 13392

   This was a little tricky as I think that the sort functions are in
   fact RR specific class attributes that should be accessed through
   class methods. This is difficult to implement. I do think I found a
   fairly clean manner. It does require a global variable in Net::DNS
   to store the functions and some trickery when the sorting functions
   are defined.

   See Net::DNS and Net::DNS::RR documentation for details.

   Defaults sorting functions are currently implemented in 
      SRV: default sort: low priority to high priority and for
           same preference highest weight first.
	   weight: sort all RRs based on weight, highest first
	   priority: see default sort

      MX:  default sort: lowest preference first.
           preference: see default sort    
    NAPTR: default sort: lowest to highest order, for same order lowest
           preference first
	   order: see default sort
	   preference: order on preference, lowest first

      PX:  See MX
      RT:  See MX

Fix 14653 and 14049 
   TCP fallback after V6 socket failure 

   Reworked Net::DNS::Base::Nameserver::send_tcp() to fallback to IPv4 when 
   possible. (change applied to SVN Revision 538).

Feature Cleanup duplicated code

   axfr_send() and send_tcp() contained some duplicated code. I merged
   this in one "helper" method _create_tcp_socket()

Fix AXFR persistent sockets colliding with query sockets.

   I think that using the same persistent sockets for AXFR and
   'ordinary' queries could lead to race conditions. Better safe than
   sorry. For axfrs we create a different set of persistent sockets.

   Note that this prevents performing a SOA query first and then using
   the same socket for the zone transfer itself(in Net::DNS these are
   different code paths). This behavior of SOA and transfer on the
   same socket-- seems to be suggested by 1035 section 4.2.2:

     "In particular, the server should allow the SOA and AXFR request
     sequence (which begins a refresh operation) to be made on a
     single connection."

   Obviously, on the client side this behavior is not mandatory.

Fix 17596
    The fixes and features above also fixed the timeout problem reported by
    Paul Hoffman


    It turned out that each time we were calling
    Net::DNS::Resolver::Base::nameserver(); We were creating a
    resolver object. Now a resolver object is only called when a
    domain name is given as argument.

**** 0.55 December 14, 2005

Fix Inconsistency in test

   There was an inconsistency in the t/05-rr.t that got triggered by
   the release of Net::DNS::SEC version 0.13 (when installed). That
   has been fixed.

Feature Net::DNS::Nameserver loop_once()

   Uncommented the documentation of the loop_once() function and introduced
   get_open_tcp() that reports if there are any open TCP sockets (useful
   when using loop_once().

   loop_once() itself was introduced in version 0.53_02

Fix 16392

   TCP Sockets stayed open even if not requested. This may cause the kernel
   to run out of TCP slots. 

   This bug is the reason for releasing version 0.55 shortly after 0.54.

   Spotted and patched by Robert Felber.

*** 0.54 December 7, 2005

Fix 15947

  Failure to bind a nameserver when specifying an IPv6 address.

Fix 11931

  Using Net-DNS 0.53 on Win XP, it is unable to retrieve the
  nameservers when the IP address of the interface is assigned by
  DHCP.  This is due to the DHCP assigned IP address being stored in
  DhcpIPAddress rather than IPAddress (which is then  Adding
  a check of DhcpIPAddress existence and not being fixes the
  problem.  Applied the patch submitted by "orjan". 

Fix 15119

  main_loop() consumed 100% of CPU, because of a bug that
  caused loop_once() to loop ad infinitum.

Fix 15299

  Defining multiple constants with 'use constant { BLA => 1, FOO =>2 };
  is a backwards incompatible feature. Thanks to Ian White for spotting and
  fixing this.

*** 0.53_02 Oct 18, 2005

Fix 14046

  RRSIGs verify and create failed for a number of RR types. The 
  error message showed something like:
      Can't call method "dn_comp" on an undefined value 
  This was caused by an omission in the _canonicalRdata() method
  in Net::DNS::RR that was inherited by all failing RR types.

  Code was added to t/05-rr.t that will test signature creation
  if Net::DNS::SEC is available and can be loaded.

Feature async nameserver behaviour.
   In 14622 Robert Stone suggested:

      The fact that it needs to take over the main running thread
      limits its audience.  Since many daemon programs are already
      driven by a top level select loop, it seems useful to provide an
      API for the user to integrate Net::DNS::Nameserver processing to
      their own select loop.

   He also supplied example code for which he is hereby acknowledged.
   The patch was not used because simultaneously Robert Martin-Legène
   supplied a patch to that allowed the same async
   functionality through the use of loop_once method. Robert M-L's 
   code also carefully manages the TCP sockets, so that they can 
   deal with AXFRs.

   Robert S. has been so kind to review Robert M-L's code and is hereby
   kindly acknowledged.

   NB. Since the code may be subject to change the documentation of the
   loop_once method has been commented out.

Fix bgsend srcaddr for IPv6 Achim Adam previously noticed that the
  source address wildard "::" works provides better portability than
  "0". We forgot to fix the bgsend() part earlier.

Fix 14624 

  Fixed documentation of Replyhandler and fixed a bug
  that prevented the peerhost to be set.

Fix 14700

  mistyped _name2wire helper function name. Noticed and patched by Simon 

Fix 13944

  Terminating dot not printed when printing SRV record. The SRV dname should
  be printed as FQDN, that is, including the dot at the end.
  Acknowledgments Jakob Schlyter. 

  While adding the "dot" I noticed that in the fileformat parsing code
  there might be theoretical corner cases where rdata elements are not
  properly read. The code needs an audit for this.

Fix srcport for socket creation in bgsend method

   Lionel Cons noted and patched a small bug in bgsocket creation code for

*** 0.53_01 July 31, 2005

Fix 13809

   "Phar" noted that the peerhost is never passed to the make_reply function
   in and provided the trivial patch. 

Fix 13922

    Fixed a problem with persistent TCP sockets which was introduced
    because of using the address family as an index to the array of
    persistent sockets. 

    Used AF_UNSPEC for the array index for the TCP socket; just to choose
    a number. The key to the persistent sockets is the remote nameserver:port 

    Acknowledgments to Mike Mitchell for reporting the bug and testing
    the solution.

Feat t/01-resolve will not try to do tests from private IP space; hopefully
    that cuts down on the number of false positives.

*** 0.53 July 22, 2005

Fix 13669

    Danny Thomas provided a somewhat more elegant line of code for the 
    typesbyval regexp.

Fix 13534 

    Net::DNS::Resolver::Recurse would bail out when it happened to run
    into lame servers.

Doc 13387

    Documented the BUG caught by Robert Martin-Legène
    Net::DNS::Nameserver running with multiple IP interfaces might
    violate section 4 of RFC2181.

Fix IPv6 on AIX

    Binding to the local interface did not work when local address was
    specified as "0" instead of "::". The problem was identified,
    reported and fixed by Achim Adam.

Fix 13232
    One uncaught AF_INET6.

*** 0.52 July 1, 2005


    added the the size(), do(),set_do() and clear_do() methods.

*** 0.51_02 June 22, 2005

Fix 13297 

    Persistent_udp option broken starting in version 0.50.
    This was fixed, based on a patch by Sidney Markowitz.
    Guido van Rooij independently submitted a similar patch.
Fix 13289 	
    Was caused by a typo. 

Fix 13243 and 13191 

    The escaped characters test failed on some system because the 
    the systems dn_expand instead of the supplied dn_expand 
    was used after the makemaker magic linked DNS.xs.

    This was fixed by renaming the dn_expand that comes with the
    library to netdns_dn_expand.

Fix 13239:

    When queries are refused the resolver would not take the next
    nameserver on the nameserver list for its next try but skip one.

    I was also made aware that the "use byte" pragma is incompatible
    with pre 5.06 perl. 

    BEGIN { 
          eval { require bytes; }

    It should be noted that for perl versions < 5.006 I had to disable
    the escaped character test. Don't expect domain names with labels
    that contain anything else than host names to work for versions
    earlier than perl 5.6.0.

    Thanks to Vladimir Kotal for the assistance in testing the code on
    his system and the members of the NL-PM list for suggestions and

*** 0.51_01 June 14, 2005

Fix 13232:

    Replaced IF_INET6 by IF_INET6() so that use strict subs does not
    complain in the absence of a definition of IF_INET6 in earlier
    versions perl that did not have IF_INET6 defined in
    The problem is similar to the problem described in:

*** 0.51 June 10, 2005

Fix 13184:

     Removed a 'stale' debug line (oops).  A "stale" debug line may
     cause clutter in log files which may cause false positives on log
     analysis tools. Harmful enough to warrant a quick patch.

*** 0.50 June 8, 2005

No changes with respect to 0.49_03.

*** 0.49_03  June 1, 2005  (Version 0.50 release candidate 3)

      Concatenation of scalars caused modification of data because of 
      Perl's habit to treat scalars as utf characters instead of bytes.
      Inserted use bytes pragma throughout the code base. DNS is done
      in octets.

      Added "ignqrid" as an attribute to the Resolver.

      use as:
      ok (my $res=Net::DNS::Resolver->new(nameservers => [''],
				    port => 5354,
				    recurse => 0,
				    igntc => 1,
				    ignqrid => 1,
      When the attribute is set to a non-zero value replies with the
      qr bit clear and replies with non-matching query ids are
      happily accepted. This opens the possibility to accept spoofed

      It is set to 0 per default and remains, except for this changes file
      an undocumented feature.

*** 0.49_02  May 28, 2005  (Version 0.50 release candidate 2)

Fix: Smoking Gun tests for non-cygwin Win32.
      Makefile.PL failed to produce a proper Makefile under win32.
      (e.g. www,
      I worked around that by moving the library into the base
      directory of the distribution as the "subdir" section 
      seemed to be all funny.

Fix: (the off-topic part)

      Sidney Markowitz spotted an awkward condition that rarely happens but is
      significant enough to be dealt with.

      In the send_udp method there are two loops: one over the nameservers
      and one that waits for the sockets to come forward with data.

      That second loop will sometimes timeout and then be entered with a 
      repeated query to the same nameserver. It occasionally happens that the
      old packet arrives on the socket. That packet is discarded but the 
      loop does not return to the loop to wait for the remainder of the
      timeout period for an answer on the second query, that may still arrive.
      This has now been fixed.

      Thanks to Sidney for the assessment of the problem and the fix.

*** 0.49_01    (Version 0.50 release candidate 1)

Fix: Makefile.PL: Minor tweak to recognize Mac OS X 10.4 not so relevant
    since netdnslib is distributed with the code.

Feature: Calling the Net::DNS::Resolver::dnssec method with a non-zero
    argument will set the udppacketsize to 2048. The method will
    also carp a warning if you pass a non-zero argument when
    Net::DNS::SEC is not installed.

Feature: IPv6 transport support
     IPv6 transport has been added to the resolver and to the
     nameserver code.
     To use IPv6 please make sure that you have IO::Socket::INET6 version
     2.01 or later installed.

     If IPv6 transport is available Net::DNS::Resolver::Recurse will make
     use of it (picking randomly between IPv4 and IPv6 transport) use
     the force_v4() method to only force IPv4.

Feature: Binary characters in labels

     RFC 1035 3.1:
       Domain names in messages are expressed in terms of a sequence of
       labels.  Each label is represented as a one octet length field
       followed by that number of octets.  Since every domain name ends
       with the null label of the root, a domain name is terminated by a
       length byte of zero.  The high order two bits of every length octet
       must be zero, and the remaining six bits of the length field limit
       the label to 63 octets or less.
     Unfortunately dname attributes are stored strings throughout
     Net::DNS.  (With hindsight dnames should have had their own class
     in which one could have preserved the wire format.).
     To be able to represent all octets that are allowed in domain
     names I took the approach to use the "presentation format" for
     the attributes. This presentation format is defined in RFC 1035
     I added code to parse presentation format domain names that has
     escaped data such as \ddd and \X (where X is not a number) to
     wireformat and vice verse. In the conversion from wire format to
     presentation format the characters that have special meaning in a
     zone file are escaped (so that they can be cut-n-pasted without
     These are " (0x22), $ (0x24), (0x28), ) (0x29), . (0x2e) , ;
     (0x3b), @ (ox40) and \ (0x5c). The number between brackets
     representing the ascii code in hex.
     Note that wherever a name occurs as a string in Net::DNS it is
     now in presentation format.
     For those that dealt with 'hostnames' (subset of all possible
     domain names) this will be a completely transparent change.
     I added netdnslib which contains Net::DNS's own dn_expand. Its
     implemented in C and the source is a hodgepodge of Berkeley based
     code and snippets from ISC's bind9 distribution. The behavior, in
     terms of which chars are escaped, is similar to bind9.
     There are some functions added to that do conversion from
     presentation and wire format and back. They should only be used
     internally (although they live in EXPORT_OK.)
     For esoteric test cases see t/11-escapedchars.t.
Fix: #11931 
     Applied the patch suggested by "Sidney". It is a practical workaround
     that may not be portable to all versions of the OS from Redmond. See
     the ticket for details.

*** 0.49 March 29, 2005

     No changes wrt 0.48_03.

*** 0.48_03 March 22, 2005 (Version 0.49 release candidate 3)

Fix: Only remove leading zeros in the regular expressions for typesbyval
     and classbyval methods. (patch by Ronald v.d. Pol)

Fix: Properly return an empty array in the authority, additional and answer
     methods (patch by Ronald v.d. Pol)

Fix: #11930 
     Incorrect searchlist duplication removal in Net::DNS::Resolver::Win32 
     Patch courtesy Risto Kankkunen.

Problem: #11931 used the DNSRegisteredAdapters registry key to determine which
     local forwarders to send queries to. This is arguably the wrong key as it
     is used to identify the server which to send dynamic updates to.

     A real fix for determining the set of nameservers to query has not been
     implemented. For details see

*** 0.48_02 March 14, 2005 (Version 0.49 release candidate 2)

Fix: Bug report by Bernhard Schmidt (concerning a bug on the IPv6 branch).

      The bug caused dname compression to fail and to create
      compression pointers causing loops.

*** 0.48_01 March 7, 2005 (Version 0.49 release candidate 1)

Fix:  #8882  
      No redundant lookups on SERVFAIL response 
     and #6149 	 
      Does not search multiple DNS servers
      Net::DNS::Resolver will now use the other nameservers in the
      list if the RCODE of the answer is not NOERROR (0) or NXDOMAIN
      (3). When send() exhausted the last nameserver from the it will
      return the answer that was received from the last nameserver
      that responded with an RCODE.

      The errorstring will be set to "RCODE: <rcode from last packet>"

Fix: #8803 
      TXT records don't work with semicolons 

      Since we are expecting "zonefile" presentation at input 
      a comment will need to be escaped ( \; ).

      It could be argued that this is a to strict interpretation of 
      1035 section 5.1.

      While working on this I discovered there are more problems with
      TXT RRs. Eg; 0100 is a perfectly legal character string that
      should be represented as "\000" in a zonefile. Net::DNS does 
      pass character strings with "non-ASCII" chars from the wire
      to the char_str_lst array but the print functions do not
      properly escape them when printing.

      Properly dealing with zonefile presentation format and binary 
      data is still to be done.

Fix: Ticket #8483 
	eval tests for DNS::RR::SIG fail when using a die handler 
	(Thanks Sebastiaan Hoogeveen)
      Patch applied.

Fix: Ticket #8608 
	Net::DNS::Packet->data makes incorrect assumptions

      Implemented the "pop" method for the question.
      Since having a qcount that is not 1 is somewhat rare (it appears
      in TCP AXFR streams) the ability to pop the answer from a question
      has not been documented in the "pod"

      Also fixed the incorrect assumption.

      (Thanks Bruce Campbell.)

Fix: Ticket #11106 
      Incorrect instructions in README 

      Corrected in the README and in Makefile.PL

Olaf Kolkman took over maintenance responsibility from Chris
Reinhardt. This involved importing the code into another subversion
repository. I made sure the numbers jumped, but I did not have access
to the "original" subversion repository so I lost some of the history.

*** 0.48 Aug 12, 2004

Net::DNS is now stored in a subversion repository, replacing cvs.
As such the submodule version numbers have taken another big jump. 
Luckily those numbers don't matter as long as they work.

Fixed a bug with Unknown RR types that broke zone signing [Olaf].

Added callback support to Net::DNS::Resolver::Recurse.  The
demo/ script demonstrates this.

Added a note regarding answers with an empty answer section to the 
Net::DNS::Resolver::search() and Net::DNS::Resolver::query() 

The copyright notice for Net::DNS::RR::SSHFP was incorrect.  That file
is Copyright (c) 2004 RIPE NCC, Olaf Kolkman.

*** 0.47_01 May 6, 2004

** NOTICE **

RR subclasses no longer pull in parts of Net::DNS; Net::DNS is assumed
to be up and running when the subclass is compiled.  If you were using a
RR subclass directly, this may break your code.  It was never documented
that you could use them directly however, so hopefully you never did...

Fixed bug where SRV records with a priority of 0 did not function 
correctly.  CPAN #6214

Calls to various constants where using the &NAME syntax, which is not
inlined.  Changed to NAME().

Added SSHFP support. [Olaf]

CERT fixes.  [Olaf]

*** 0.47 April 1, 2004

safe_push() is back in Net::DNS::Packet, due to the excellent debate
skills of Luis E Munoz.  However, the name safe_push() is deprecated,
use the new name unique_push() instead.

Fixed a bug in Net::DNS::Nameserver which caused the class to build 
packets incorrectly in some cases. [Ask Bjorn Hansen]

Error message cleanups in Net::DNS::typesbyname()
and Net::DNS::typesbyval() [Ask Bjorn Hansen]

Net::DNS::RR::new_from_hash() now works with unknown RR types [Olaf].

*** 0.46 February 21, 2004

IPv6 reverse lookups can now be done with Net::DNS::Resolver::search(),
as well as with query().

Hostnames can now be used in the 'nameservers' argument to 

*** 0.45_01 February 9, 2004

Net::DNS now uses UDP on windows.

Removed Net::DNS::Select from the package.  IO::Select appears to work
on windows just fine.

Fixed a bug that caused MXes with a preference of 0 to function
incorrectly, reported by Dick Franks.

Net::DNS had a few problems running under taint mode, especially under
cygwin.  These issues have been fixed.  More issues with taint mode may
lie undiscovered.

Applied Matthew Darwin's patch added support for IPv6 reverse lookups to

*** 0.45 January 8, 2004

No changes from 0.44_02.

** 0.44_02 January 3, 2004

The XS detection code was broken.  We actually use the XS bits now.

Major cleanups/optimizations of the various RR subclasses.  This release
of Net::DNS is over twice as fast at parsing dns packets as 0.44.

** NOTICE **

$rr->rdatastr no longer returns '; no data' if the RR record has no
data.  This happens in $rr->string now.

Net::DNS::Packet::safe_push() no longer exists.  The method is now only 
available from Net::DNS::Update objects.

** 0.44_01 January 3, 2004

Net::DNS::RR objects were not playing nice with Storable, this caused 
the axfr demo script to fail.  Thanks to Joe Dial for the report.

** NOTICE **
This may cause RR objects that are already serialize to not deserialize

Reply handlers in Net::DNS::Nameserver are now passed the query object.

Fixed a nasty bug in related to the qr bit.  As Olaf

  Replies are sent if the query has its "qr" bit set. The "qr" bit is an
  indication that the packet is sent as a response to a query. Since
  there are more implementations that suffer from this bug one can cause
  all kinds of nasty ping-pong loops by spoofing the initial packet or
  have an infinite query loop by spoofing a query from the localhost:53

Various Win32/Cygwin cleanups from Sidney Markowitz.

*** 0.44 December 12, 2003

	The Wrath of CPAN Release. doesn't understand the nature of revision numbers.  1.10 is 
newer than 1.9; but treats them as floats.  This is bad.
All the internal version numbers in Net::DNS have been bumped to
2.100 in order to fix this.

No actual code changes in this release.

*** 0.43 December 11, 2003

Added warning of deprecation of Net::DNS::Packet::safe_push.  This will
move into Net::DNS::Update, as Net::DNS::Update is now a proper subclass
of Net::DNS::Packet.

** 0.42_02 December 11, 2003

Fixed a long standing bug with zone transfers in the "many-answers" format. 
CPAN #1903.

Added the '--online-tests' flag to Makefile.PL.  This activates the online
tests without asking the user interactively.  "--no-online-tests" turns
the tests off.  

Cleaned up Makefile.PL a little.  The "--pm" flag is now deprecated, use
"--no-xs" instead.

Added support for unknown RR types (rfc3597). Note for developers: the
typesbyname, typesbyval, classesbyname and classesbyval hashes should
not be used directly, use the same named wrapper functions
instead. [Olaf Kolkman]

Added two hashes for administrative use; they store which types are
qtypes and metatypes (rfc2929). [Olaf Kolkman]

** 0.42_01 November 30, 2003

Major work to get Net::DNS functioning properly on Cygwin by Sidney 

Fixed a bug in Net::DNS::Nameserver's error handling.  CPAN #4195

*** 0.42 October 26, 2003

Fixed compilation problems on panther (Mac OS 10.3).

Fixed a bug in Net::DNS::Resolver::Recurse which allowed an endless
loop to arise in certain situations.  (cpan #3969, patch
by Rob Brown) 

Applied Mike Mitchell's patch implementing a persistent UDP socket.  
See the Net::DNS::Resolver documentation for details.

*** 0.41 October 3, 2003

Added some documentation about modifying the behavior of Net::DNS::Resolver. 

** 0.40_01 September 26, 2003

Fixed some uninitialized value warnings when running under windows.

Fixed a bug in the test suite that caused 00-version.t to fail with
certain versions of ExtUtils::MakeMaker.   Thanks to David James, Jos 
Boumans and others for reporting it.

Reply handlers in Net::DNS::Nameserver are now passed the peerhost.
(Assen Totin <>)

Reply handlers in Net::DNS::Nameserver can now tweak the header bits
that the nameserver returns.  [Olaf]

The AD header bit is now documented, and twiddlable. [Olaf]

The change log has been trimmed, entries for versions older than 0.21
have been removed. 

** NOTICE **
Net::DNS::Resolver::axfr_old() has been removed from the package.  
An exception will be thrown if you attempt to use this method.  Use
axfr() or axfr_start() instead.

*** 0.40 September 1, 2003

Various POD tweaks.

** 0.39_02 August 28, 2003

Net-DNS-SEC updates, seems that IETF has been busy redefining DNSSEC.

Added version to all the modules in the distribution.

** 0.39_01 August 12 2003

Added a META.yaml.  The crystal ball says an upgrade to Module::Install may
be coming soon.

Changed how the versions of the various submodules were set.  The CPAN 
indexer cannot execute "$VERSION = $Net::DNS::VERSION".  The single line
with the $VERSION assignment is pulled out of the file and eval'ed; at
that time, Net::DNS is not loaded.  The submodules now pull their version 
numbers out of CVS.

*** 0.39 August 7 2003

Fixed a bug on Win32 where some machines separated lists with commas, 
not whitespace.  Thanks to Jim White for pointing it out.

** 0.38_02 July 29 2003

Reworked the POD for Net::DNS::Resolver.

When parsing resolver configuration files, IPv6 addresses are now skipped,
as Net::DNS does not yet have IPv6 support. 

** 0.38_01 Jun 22 2003

Broke Net::DNS::Resolver into separate classes.  UNIX and Win32 
classes are currently implemented.  Many of the globals in 
Net::DNS::Resolver no longer exist.  They were never documented
so you never used them.... right?
Options to Net::DNS::Resolver->new() are now supported, including
using your own configuration file.  See the Net::DNS::Resolver man
page for details.

Tweaked Net::DNS::RR::TXT to fail more gracefully when the quotes 
in the data section are not balanced.

Add more tests (of course).

Moved next_id() from to (which is where it is

Net::DNS::Select now uses $^O directly, this means that the second
argument to Net::DNS::Select::new() (the OS) is now ignored.

*** 0.38 Jun 5 2003

Various buglets fixed in the new Makefile.PL.

Use Dynaloader instead of XSLoader.  Turns out that XSLoader is only 
in more recent perls.

Added deprecation warning to Net::DNS::Resolver::axfr_old().

HP-UX fixes [cpan #2710], I don't have the name of the reporter/patcher.

*** 0.37 May 28 2003

Renamed the test C file to compile.c, test.c was confusing the 'make test'

*** 0.36 May 28 2003

Removed Rob Brown's RPM stuff.  Something odd happened in the 0.35 tarball
and at the moment I don't have the time to investigate.

*** 0.35 May 26 2003

POD fixes, added tests for POD.

*** 0.34_03 May 22 2003

Reworked Makefile.PL to try and detect if you have a working C compiler.

Added '--pm' and '--xs' command line options to Makefile.PL

Fixed linking problem on linux.

Tie::DNSHash removed from the package, see Tie::DNS from CPAN for a more
complete implementation of a DNS hash.

*** 0.34_02 May 21 2003

Net::DNS::Packet::dn_expand is now implemented using the function of the
same name from libresolv.  This method of decompressing names is around
twice as fast as the perl implementation.

Applied Jan Dubois's patch to fix nameserver lookup on Windows 2000/95/98/ME.

*** 0.34 6 Mar 2003

Applied David Carmean's patch for handling more than one string in a 
TXT RR's RDATA section.

Applied Net::DNS::Resolver::Recurse bug fixes from Rob Brown.

Added check of the answer's rcode in Net::DNS::Resolver::axfr_next().

Applied Kenneth Olving <> Windows changes.

Applied patch from Dan Sully ( allowing multiple
questions to be part of a DNS packet.

*** 0.33 8 Jan 2003

Fixed 00-load.t to skip the Net::DNS::SEC modules.  The test suite
should now pass if you have Net::DNS::SEC installed. 

Fixed the regular expression in to comply with the RFCs, turns
out we were _too_ paranoid.  [Olaf]

*** 0.32 5 Jan 2003

Various cleanups for perl 5.004.  Thanks to
([cpan #1847])

Applied Olaf's SIG patch (thanks as always).

Win32 now looks at the environment variables when building the 
configuration defaults.  Thanks to 
(That's the only name I have... [cpan #1819])

Added Rob Brown's Net::DNS::Resolver::Recurse module.

*** 0.31 17 Nov 2002

Applied Olaf's patch for an initialization bug in

Applied Rob Brown's patch for udp timeouts.

Added stuff from Rob Brown for making RPM creation easier.

Fixed a typo in FAQ.pod that was making apropos and whatis
grumpy.  Thanks to Florian Hinzmann for pointing it out and a patch.

*** 0.30 7 Nov 2002

Applied Andrew Tridgell's ( patch for TKEY support.

Added Net::DNS::Packet->safe_push() to allow for automatically
checking for duplicate RRs being pushed into a packet.  Inspired by Luis

Added more tests.

*** 0.29 2 Oct 2002

Fixed $_ from creeping out of scope in Thanks to
Ilya Martynov for finding the problem and the patch to fix it.

Fixed divide by zero bug there is no usable network interface(s).
Thanks to, misiek@pld.ORG.PL (and one other
person that I can't seem to find the address of) for reports. 

*** 0.28 20 Aug 2002

Fixed a bug in the new AUTOLOAD routines that made it impossible to set
attributes to '0'.

Fixed a bug in the RR patch that broke many updates. 

*** 0.27 15 Aug 2002

Added (untested) support for perl 5.004.

We now allow whitespace at the beginning of a RR.

Fixed an issue that gave Net::DNS::SEC problems, %Net::DNS::RR::RR is now 
in a scope that the Net::DNS::SEC hook can see it from.

Fixed SRV records.

Fixed debug message in Net::DNS::Resolver::bgread().

*** 0.26 5 Aug 2002

Fixed various bugs in the test suite.

Fixed warning in Net::DNS::RR::AUTOLOAD with perl 5.005.

Olaf Kolkman <>
Chris Reinhardt 
Michael Fuhr