Releases: PururinCollective/elpis-resolver
Release list
v2.0.1
ΕΛΠΙΣ Resolver 2.0.1
The first 2.x release: Elpis after a full release review, meant to be left running. These notes cover everything since 1.1.15, including the 2.0.0 work.
✨ Highlights
- 🔐 Stripped signatures are caught behind a forwarder. With
forward-zone: ., an unsigned answer is now followed down the signed tree through the forwarder. If its zone is signed, an answer whose DNSSEC signatures were removed is refused instead of served. - ⚡ Faster first lookups on DNS-provider zones. Zones hosted on Google Cloud DNS, Route 53 or Azure DNS now use their nearest nameserver. New Telegram hostnames went from 164 ms to 7–9 ms.
- 🧠 Failures are remembered (RFC 9520). A name that fails to resolve gets an instant SERVFAIL, with EDE 13 "Cached Error", for 5 to 60 seconds, instead of another slow attempt on every retry.
- 🌐 DNS64 fixed and extended. Synthesis now works behind DNSSEC-aware forwarders such as AdGuard Home, so 464XLAT devices can find the prefix through
ipv4only.arpa. The newdns64-strip-a: yesgives clients IPv6-only DNS without turning IPv4 off. - ✅ Validation fixes.
www.hasil.gov.my(LHDN) resolves again. NXDOMAIN answers proven through NSEC3 opt-out no longer carry AD (RFC 5155 §9.2). - 🧹 Clean shutdown. Lookups and TCP clients still in flight at exit are freed, so ASan and valgrind report nothing.
- 🖥️ Status page. The title is now ΕΛΠΙΣ, the login name is no longer pre-filled, and the About window's build shows the release (
v2.0.1) instead of a commit hash with-dirty.
⚠️ Upgrading from 1.x
One change of meaning makes this 2.0. Behind forward-zone: ., a private zone that your upstream serves must now be routed here too:
forward-zone: . 10.0.0.53
forward-zone: corp 10.0.0.53
Apart from that, no config that worked stops working.
📊 Performance
28 groups of popular services (Google, YouTube, Steam, Epic, Telegram, Microsoft and Windows Update, Apple, Discord, GitHub, Shopee, Taobao, Malaysian banks and more): 1,221 lookups, each host asked A, AAAA and HTTPS at once, as a browser asks.
| median | 90th percentile | 99th percentile | |
|---|---|---|---|
| Elpis, answered from cache | 0.6 ms | 1.1 ms | 1.5 ms |
| Elpis, cold cache (full recursion) | 82 ms | 269 ms | 709 ms |
| 1.1.1.1, from the same machine | 4.2 ms | 15.5 ms | 170 ms |
Elpis's answers matched 1.1.1.1's on 1,218 of the 1,221 lookups. Of the other three, two were CDNs answering by location, and one was a name 1.1.1.1 failed to resolve.
📦 Install
elpis-resolver-2.0.1_linux-amd64.tar.gz is for Linux on x86-64.
tar -xzf elpis-resolver-2.0.1_linux-amd64.tar.gz
sudo mkdir -p /opt/elpis-resolver/bin
sudo cp elpis elpis.conf /opt/elpis-resolver/bin/
/opt/elpis-resolver/bin/elpis -t # check the config and exitTo build from source for other CPUs and platforms, see COMPILING.md.
📝 Every change in detail is in the changelog.