Skip to content

Releases: skitzo2000/espDNS

Release list

espDNS 0.0.1

espDNS 0.0.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 08 Oct 00:55

The first numbered version: everything built so far, from the node firmware and the
controller's first pages to the security review's fixes and the backend of the redesigned GUI.

Added

  • Versions: the repository's VERSION is the firmware's version (its app descriptor's, so
    /status, the image header and the controller say it, no longer git describe) and the
    controller's (espdns version, /api/session, its log). Firmware updates are ordered by
    version, the build time breaking a tie between two builds of one version.
    scripts/bump-version.sh moves to the next version.
  • The node: a small OS on ESP32-P4 and ESP32-S3 boards (wired Ethernet, Wi-Fi as a fallback,
    microSD): the services its config enables (hosted zones, secondary zones over AXFR,
    forwarding, a cache, blocking, a query log), board definitions as data, a memory plan from
    board data, health states and LEDs, /status, /metrics and the query log with a cursor.
    It takes only signed releases (ECDSA P-256, bound to the node, board and a sequence number).
  • Blocking: lists compiled by the controller (adblock, hosts, domains, wildcard and RPZ
    sources, allow lists, overrides), placed in the node's memory tiers, with a size-change
    check, a list canary, a soak and a revert to the older list the node keeps.
  • The controller (one Go binary with a web UI, run with Docker Compose) and its CLI
    (espdns): discovery, adoption, node configs and their editor, the zone editor, any zone
    primary (manual, or Technitium's API as a driver), rolling pushes that never take down the
    last healthy node, a dashboard and the query log, backup, restore and recovery from the
    nodes.
  • The GUI's backend for the redesign: zone inventory and zone lookup; pending changes and
    one apply job that sends them; the node settings form, its edits as pending changes;
    firmware update availability, shown as versions; one search across nodes, zones and
    lists; the first run and settings.json from the browser; and looking up a node to add
    by its address.
  • Forwarding: a table of the upstream queries in flight, with caps per group.
  • Hosted zones: a revert to the older bundle the node keeps, from the firmware, the CLI, make,
    a controller job and the Zones page.

Changed

  • Hosted zones are held in canonical order, with a binary search for a name's existence, and
    to their memory limit; an AXFR and its SOA check run within one deadline.
  • The test vectors, fixtures and tests use documentation addresses and names only, and CI
    refuses private ones.

Security

  • The controller loads esp-web-tools from its own vendored copy (10.4.0), not from a CDN.
  • The controller sends a strict Content Security Policy and security headers on every
    response, with no inline scripts.
  • Firmware builds: no key and no network in the build containers, signing in a step of its
    own, and container images and CI actions pinned by digest.
  • The node's HTTP server checks the Host header against DNS rebinding, gives each request one
    deadline, applies releases in a worker, and JSON-escapes /status.
  • Controller sessions are bound to the page's origin, logins back off per client, and a backup
    or a revealed Wi-Fi password asks for the password again.
  • The controller's data directory is the user's only (directories 0700, files 0600), and its
    container is hardened: no capabilities, no new privileges, a read-only root, memory and
    process limits.

Every file is listed in SHA256SUMS, signed with the espDNS release key in SHA256SUMS.sig:
check them before use as docs/releasing.md, Checking a release, says.