diff options
| author | rawnix ports <ports@rawnix.org> | 2026-09-26 18:19:05 +0000 |
|---|---|---|
| committer | rawnix ports <ports@rawnix.org> | 2026-09-26 18:19:05 +0000 |
| commit | c82e88dd00d1b0b7fcfb4e5628d99611388cef6f (patch) | |
| tree | 56d864b5a5c6c145edd96178ae219a8f90e191a6 /opt/unbound | |
| download | ports-c82e88dd00d1b0b7fcfb4e5628d99611388cef6f.tar.gz | |
sync 2026-09-26 18:19 UTC
1672 files changed, 151396 insertions(+)
Diffstat (limited to 'opt/unbound')
| -rw-r--r-- | opt/unbound/.footprint | 73 | ||||
| -rw-r--r-- | opt/unbound/.signature | 6 | ||||
| -rw-r--r-- | opt/unbound/MAKEPKG | 172 |
3 files changed, 251 insertions, 0 deletions
diff --git a/opt/unbound/.footprint b/opt/unbound/.footprint new file mode 100644 index 0000000..522d5fa --- /dev/null +++ b/opt/unbound/.footprint @@ -0,0 +1,73 @@ +drwxr-xr-x root/root etc/ +drwxr-xr-x root/root etc/sv/ +drwxr-xr-x root/root etc/sv/unbound/ +-rwxr-xr-x root/root etc/sv/unbound/finish +-rwxr-xr-x root/root etc/sv/unbound/run +drwxr-xr-x root/root etc/sv/unbound/log/ +-rwxr-xr-x root/root etc/sv/unbound/log/run +drwxr-x--- root/root etc/unbound/ +-rw-r--r-- root/root etc/unbound/unbound.conf +drwxr-xr-x root/root usr/ +drwxr-xr-x root/root usr/bin/ +-rwxr-xr-x root/root usr/bin/unbound +-rwxr-xr-x root/root usr/bin/unbound-anchor +-rwxr-xr-x root/root usr/bin/unbound-checkconf +-rwxr-xr-x root/root usr/bin/unbound-control +-rwxr-xr-x root/root usr/bin/unbound-control-setup +-rwxr-xr-x root/root usr/bin/unbound-host +drwxr-xr-x root/root usr/include/ +-rw-r--r-- root/root usr/include/unbound.h +drwxr-xr-x root/root usr/lib/ +-rw-r--r-- root/root usr/lib/libunbound.a +drwxr-xr-x root/root usr/lib/pkgconfig/ +-rw-r--r-- root/root usr/lib/pkgconfig/libunbound.pc +drwxr-xr-x root/root usr/share/ +drwxr-xr-x root/root usr/share/man/ +drwxr-xr-x root/root usr/share/man/man1/ +-rw-r--r-- root/root usr/share/man/man1/unbound-host.1.gz +drwxr-xr-x root/root usr/share/man/man3/ +-rw-r--r-- root/root usr/share/man/man3/libunbound.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_cancel.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_add_ta.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_add_ta_file.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_async.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_config.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_create.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_data_add.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_data_remove.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_debuglevel.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_debugout.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_delete.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_get_option.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_hosts.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_print_local_zones.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_resolvconf.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_set_fwd.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_set_option.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_trustedkeys.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_zone_add.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_ctx_zone_remove.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_fd.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_poll.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_process.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_resolve.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_resolve_async.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_resolve_free.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_result.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_strerror.3.gz +-rw-r--r-- root/root usr/share/man/man3/ub_wait.3.gz +drwxr-xr-x root/root usr/share/man/man5/ +-rw-r--r-- root/root usr/share/man/man5/unbound.conf.5.gz +drwxr-xr-x root/root usr/share/man/man8/ +-rw-r--r-- root/root usr/share/man/man8/unbound-anchor.8.gz +-rw-r--r-- root/root usr/share/man/man8/unbound-checkconf.8.gz +-rw-r--r-- root/root usr/share/man/man8/unbound-control-setup.8.gz +-rw-r--r-- root/root usr/share/man/man8/unbound-control.8.gz +-rw-r--r-- root/root usr/share/man/man8/unbound.8.gz +drwxr-xr-x root/root var/ +drwxr-xr-x root/root var/lib/ +drwxr-xr-x root/root var/lib/pkg/ +drwxr-xr-x root/root var/lib/pkg/meta/ +-rw-r--r-- root/root var/lib/pkg/meta/unbound +drwxr-x--- root/root var/lib/unbound/ diff --git a/opt/unbound/.signature b/opt/unbound/.signature new file mode 100644 index 0000000..2c91296 --- /dev/null +++ b/opt/unbound/.signature @@ -0,0 +1,6 @@ +RWTZ9IduCSQ/mKT1qQuG0ECX7EjWqmMeEz5CprZP7d9WbPu15JHbcKJL2OXTqq7Q0k7bgnT57+Qhl6L/GkOFgZrZ9DN7WDmmoQU= + +SHA256 (MAKEPKG) = 6f316911ad06c9c877dedfab1ee072ef64e380af72356e5b63186c4e98dccc87 +SHA256 (.footprint) = ac11903cb5b9de76807e12e724a131c3f3e9fb73166ef733eaa0e5ba58cd5a94 +SHA256 (unbound-1.26.1.tar.gz) = 35a6dc0e425a9282c3426d9a3043144011bf0534aed4b73ab62c52aee0af1503 +SHA256 (unbound#1.26.1-1.pkg.tar.gz) = 1feffa246029aef4920ddb0d5560c9ee6efc0fc1710bbcafdfcd442964678592 diff --git a/opt/unbound/MAKEPKG b/opt/unbound/MAKEPKG new file mode 100644 index 0000000..b21edf5 --- /dev/null +++ b/opt/unbound/MAKEPKG @@ -0,0 +1,172 @@ +#!/bin/mkpkg +# description: Validating, recursive, caching DNS resolver with DNSSEC support +# url: https://nlnetlabs.nl/projects/unbound/about/ + +name=unbound +version=1.26.1 +release=1 +depends=(libressl expat) +makedeps=(flex bison) +groups=(unbound:user:unbound:/var/lib/unbound:750:904:904) +services=(unbound) +permissions=( + /usr/bin/unbound:root:unbound:750 + /usr/bin/unbound-anchor:root:unbound:4750 + /usr/bin/unbound-checkconf:root:unbound:750 + /usr/bin/unbound-control:root:unbound:750 + /usr/bin/unbound-host:root:unbound:750 + /etc/unbound/unbound.conf:root:unbound:640 +) +source=(https://nlnetlabs.nl/downloads/unbound/$name-$version.tar.gz) +sha256sums=( + "35a6dc0e425a9282c3426d9a3043144011bf0534aed4b73ab62c52aee0af1503" +) + +build() { + cd $name-$version + ./configure \ + --prefix=/usr \ + --sysconfdir=/etc \ + --localstatedir=/var \ + --sbindir=/usr/bin \ + --disable-rpath \ + --disable-shared \ + --enable-pie \ + --enable-relro-now \ + --enable-tfo-client \ + --enable-tfo-server \ + --enable-aggressive-nsec \ + --with-ssl=/ \ + --with-conf-file=/etc/unbound/unbound.conf \ + --with-pidfile=/run/unbound/unbound.pid \ + --with-chroot-dir=/var/lib/unbound \ + --with-username=unbound \ + --with-rootkey-file=/var/lib/unbound/root.key \ + --with-libevent=no \ + --without-pyunbound \ + --without-pythonmodule \ + --disable-flto + make + make DESTDIR=$PKG install + + # Remove docs and static lib noise + rm -rf $PKG/usr/share/doc + rm -f $PKG/usr/lib/libunbound.la + + # Config directory + install -d -m 750 $PKG/etc/unbound + + # Hardened default config + printf '%s\n' \ + 'server:' \ + ' # Network' \ + ' interface: 127.0.0.1' \ + ' port: 53' \ + ' do-ip4: yes' \ + ' do-ip6: no' \ + ' do-udp: yes' \ + ' do-tcp: yes' \ + '' \ + ' # Access control' \ + ' access-control: 127.0.0.0/8 allow' \ + ' access-control: 0.0.0.0/0 refuse' \ + '' \ + ' # Privilege separation' \ + ' username: "unbound"' \ + ' directory: "/var/lib/unbound"' \ + ' chroot: "/var/lib/unbound"' \ + ' pidfile: "/run/unbound/unbound.pid"' \ + '' \ + ' # DNSSEC validation' \ + ' auto-trust-anchor-file: "/var/lib/unbound/root.key"' \ + ' val-clean-additional: yes' \ + '' \ + ' # Hardening' \ + ' hide-identity: yes' \ + ' hide-version: yes' \ + ' harden-glue: yes' \ + ' harden-dnssec-stripped: yes' \ + ' harden-referral-path: yes' \ + ' harden-algo-downgrade: yes' \ + ' harden-below-nxdomain: yes' \ + ' harden-large-queries: yes' \ + ' harden-short-bufsize: yes' \ + ' use-caps-for-id: yes' \ + ' qname-minimisation: yes' \ + ' aggressive-nsec: yes' \ + '' \ + ' # Privacy' \ + ' minimal-responses: yes' \ + ' rrset-roundrobin: yes' \ + '' \ + ' # Resource limits' \ + ' num-threads: 1' \ + ' msg-cache-size: 8m' \ + ' rrset-cache-size: 16m' \ + ' key-cache-size: 8m' \ + ' neg-cache-size: 4m' \ + ' unwanted-reply-threshold: 10000' \ + '' \ + ' # Logging (minimal)' \ + ' verbosity: 1' \ + ' use-syslog: no' \ + ' logfile: ""' \ + ' log-queries: no' \ + ' log-replies: no' \ + ' log-servfail: yes' \ + > $PKG/etc/unbound/unbound.conf + + # chroot bind-mount targets + install -d -m 750 $PKG/var/lib/unbound +} + +post_build() { + # runit service + install -d $PKG/etc/sv/unbound/log + + printf '%s\n' \ + '#!/bin/sh' \ + 'exec 2>&1' \ + '' \ + '# Prepare runtime directories' \ + 'install -d -m 750 -o unbound -g unbound /run/unbound' \ + 'install -d -m 750 -o unbound -g unbound /var/lib/unbound' \ + '' \ + '# Copy TLS certs into chroot for DNSSEC anchor fetch' \ + 'install -d -m 755 /var/lib/unbound/etc/ssl' \ + 'cp /etc/ssl/cert.pem /var/lib/unbound/etc/ssl/ 2>/dev/null || true' \ + '' \ + '# Fetch/update DNSSEC root trust anchor' \ + '# unbound-anchor returns 1 if the anchor was updated (not an error)' \ + 'unbound-anchor -a /var/lib/unbound/root.key || true' \ + 'chown unbound:unbound /var/lib/unbound/root.key' \ + '' \ + '# Validate config before starting' \ + 'unbound-checkconf /etc/unbound/unbound.conf || exit 1' \ + '' \ + '# Start unbound in foreground (-d) without forking (-v for stderr)' \ + 'exec unbound -d -c /etc/unbound/unbound.conf' \ + > $PKG/etc/sv/unbound/run + + printf '%s\n' \ + '#!/bin/sh' \ + 'rm -rf /run/unbound' \ + > $PKG/etc/sv/unbound/finish + + printf '%s\n' \ + '#!/bin/sh' \ + 'mkdir -p /var/log/unbound' \ + 'exec svlogd -tt /var/log/unbound' \ + > $PKG/etc/sv/unbound/log/run + + chmod 755 $PKG/etc/sv/unbound/run + chmod 755 $PKG/etc/sv/unbound/finish + chmod 755 $PKG/etc/sv/unbound/log/run +} + +signify() { + untrusted comment: public key + RWTZ9IduCSQ/mL8337TEUinPwT92xFEUpD92hkS7IxcOnzTt9QdpohT3 +} + +# vim: filetype=sh |
