{"diffoscope-json-version": 1, "source1": "/srv/reproducible-results/rbuild-debian/r-b-build.SCy7PSmY/b1/bind9_9.19.24-185-g392e7199df2-1_amd64.changes", "source2": "/srv/reproducible-results/rbuild-debian/r-b-build.SCy7PSmY/b2/bind9_9.19.24-185-g392e7199df2-1_amd64.changes", "unified_diff": null, "details": [{"source1": "Files", "source2": "Files", "unified_diff": "@@ -1,13 +1,13 @@\n \n e9b99e865c0b257b63f6020382510016 666556 debug optional bind9-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb\n 47fb0490cf0d7b41fafc0db970736c00 552252 devel optional bind9-dev_9.19.24-185-g392e7199df2-1_amd64.deb\n 5147e4881302cd930adfc1c8d2444997 430504 debug optional bind9-dnsutils-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb\n 6114eec7dc851b65bb20634072c8a179 427104 net standard bind9-dnsutils_9.19.24-185-g392e7199df2-1_amd64.deb\n- 9ba5ee94421568ad5895fab77750c266 3496968 doc optional bind9-doc_9.19.24-185-g392e7199df2-1_all.deb\n+ 33f063eef619e55af25305aafaad3e28 3496944 doc optional bind9-doc_9.19.24-185-g392e7199df2-1_all.deb\n 3cdaab25c9df5c0aad696b869f834fb9 105476 debug optional bind9-host-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb\n 4ffbd8ee21011079e48d974c7e2bba10 317840 net standard bind9-host_9.19.24-185-g392e7199df2-1_amd64.deb\n 151c38c362b37b76fe31f6d01aa40a4e 4038924 debug optional bind9-libs-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb\n b80247560b965c8310d5ba7f5cf456f5 1465068 libs standard bind9-libs_9.19.24-185-g392e7199df2-1_amd64.deb\n 06877671140369e57d9c4745071ad614 481652 debug optional bind9-utils-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb\n 15a801324134bf246c8be6aa39bd554f 443700 net optional bind9-utils_9.19.24-185-g392e7199df2-1_amd64.deb\n abfd0e4f6d0ff50c4f7a853ca9d0538b 509300 net optional bind9_9.19.24-185-g392e7199df2-1_amd64.deb\n"}, {"source1": "bind9-doc_9.19.24-185-g392e7199df2-1_all.deb", "source2": "bind9-doc_9.19.24-185-g392e7199df2-1_all.deb", "unified_diff": null, "details": [{"source1": "file list", "source2": "file list", "unified_diff": "@@ -1,3 +1,3 @@\n -rw-r--r-- 0 0 0 4 2024-06-20 13:11:56.000000 debian-binary\n -rw-r--r-- 0 0 0 2012 2024-06-20 13:11:56.000000 control.tar.xz\n--rw-r--r-- 0 0 0 3494764 2024-06-20 13:11:56.000000 data.tar.xz\n+-rw-r--r-- 0 0 0 3494740 2024-06-20 13:11:56.000000 data.tar.xz\n"}, {"source1": "control.tar.xz", "source2": "control.tar.xz", "unified_diff": null, "details": [{"source1": "control.tar", "source2": "control.tar", "unified_diff": null, "details": [{"source1": "./md5sums", "source2": "./md5sums", "unified_diff": null, "details": [{"source1": "./md5sums", "source2": "./md5sums", "comments": ["Files differ"], "unified_diff": null}]}]}]}, {"source1": "data.tar.xz", "source2": "data.tar.xz", "unified_diff": null, "details": [{"source1": "data.tar", "source2": "data.tar", "unified_diff": null, "details": [{"source1": "./usr/share/doc/bind9-doc/arm/reference.html", "source2": "./usr/share/doc/bind9-doc/arm/reference.html", "unified_diff": "@@ -762,15 +762,15 @@\n key-directory.

\n

The following options can be specified in a key-store statement:

\n
\n
\n pkcs11-uri\uf0c1
\n

Grammar: pkcs11-uri <quoted_string>;

\n

Blocks: key-store

\n-

Tags: pkcs11, dnssec

\n+

Tags: dnssec, pkcs11

\n

The uri is a string that specifies a PKCS#11 URI Scheme (defined in\n RFC 7512). When set, named will try to create keys inside the\n corresponding PKCS#11 token. This requires BIND to be built with OpenSSL 3,\n and have a PKCS#11 provider configured.

\n
\n \n \n@@ -2752,15 +2752,15 @@\n \n \n
\n
\n zone-statistics\uf0c1
\n

Grammar: zone-statistics ( full | terse | none | <boolean> );

\n

Blocks: options, view, zone (mirror, primary, redirect, secondary, static-stub, stub)

\n-

Tags: logging, zone

\n+

Tags: zone, logging

\n

Controls the level of statistics gathered for all zones.

\n

\n

If full, the server collects statistical data on all zones,\n unless specifically turned off on a per-zone basis by specifying\n zone-statistics terse or zone-statistics none in the zone\n statement. The statistical data includes, for example, DNSSEC signing\n operations and the number of authoritative answers per query type. The\n@@ -3637,15 +3637,15 @@\n

\n \n
\n
\n check-dup-records\uf0c1
\n

Grammar: check-dup-records ( fail | warn | ignore );

\n

Blocks: options, view, zone (primary)

\n-

Tags: query, dnssec

\n+

Tags: dnssec, query

\n

Checks primary zones for records that are treated as different by DNSSEC but are semantically equal in plain DNS.

\n

\n

This checks primary zones for records that are treated as different by\n DNSSEC but are semantically equal in plain DNS. The default is to\n warn. Other possible values are fail and ignore.

\n
\n \n@@ -3766,28 +3766,28 @@\n \n \n
\n
\n zero-no-soa-ttl\uf0c1
\n

Grammar: zero-no-soa-ttl <boolean>;

\n

Blocks: options, view, zone (mirror, primary, secondary)

\n-

Tags: server, query, zone

\n+

Tags: zone, query, server

\n

Specifies whether to set the time to live (TTL) of the SOA record to zero, when returning authoritative negative responses to SOA queries.

\n

\n

If yes, when returning authoritative negative responses to SOA queries, set\n the TTL of the SOA record returned in the authority section to zero.\n The default is yes.

\n
\n \n
\n
\n zero-no-soa-ttl-cache\uf0c1
\n

Grammar: zero-no-soa-ttl-cache <boolean>;

\n

Blocks: options, view

\n-

Tags: server, query, zone

\n+

Tags: zone, query, server

\n

Sets the time to live (TTL) to zero when caching a negative response to an SOA query.

\n

\n

If yes, when caching a negative response to an SOA query set the TTL to zero.\n The default is no.

\n
\n \n
\n@@ -4680,30 +4680,30 @@\n
\n \n
\n
\n notify-rate\uf0c1
\n

Grammar: notify-rate <integer>;

\n

Blocks: options

\n-

Tags: transfer, zone

\n+

Tags: zone, transfer

\n

Specifies the rate at which NOTIFY requests are sent during normal zone maintenance operations.

\n

\n

This specifies the rate at which NOTIFY requests are sent during normal zone\n maintenance operations. (NOTIFY requests due to initial zone loading\n are subject to a separate rate limit; see below.) The default is 20\n per second. The lowest possible rate is one per second; when set to\n zero, it is silently raised to one.

\n
\n \n
\n
\n startup-notify-rate\uf0c1
\n

Grammar: startup-notify-rate <integer>;

\n

Blocks: options

\n-

Tags: transfer, zone

\n+

Tags: zone, transfer

\n

Specifies the rate at which NOTIFY requests are sent when the name server is first starting, or when new zones have been added.

\n

\n

This is the rate at which NOTIFY requests are sent when the name server\n is first starting up, or when zones have been newly added to the\n name server. The default is 20 per second. The lowest possible rate is\n one per second; when set to zero, it is silently raised to one.

\n
\n@@ -4932,15 +4932,15 @@\n \n \n
\n
\n max-records\uf0c1
\n

Grammar: max-records <integer>;

\n

Blocks: options, view, zone (mirror, primary, redirect, secondary, static-stub, stub)

\n-

Tags: server, zone

\n+

Tags: zone, server

\n

Sets the maximum number of records permitted in a zone.

\n

\n

This sets the maximum number of records permitted in a zone. The default is\n zero, which means the maximum is unlimited.

\n
\n \n
\n@@ -5363,15 +5363,15 @@\n sortlist\uf0c1\n
\n

Warning

\n

This option is deprecated and will be removed in a future version of BIND.

\n
\n

Grammar: sortlist { <address_match_element>; ... }; // deprecated

\n

Blocks: options, view

\n-

Tags: query, deprecated

\n+

Tags: deprecated, query

\n

Controls the ordering of RRs returned to the client, based on the client\u2019s IP address.

\n

\n

This option is deprecated and will be removed in a future release.

\n

The sortlist statement (see below) takes an address_match_list and\n interprets it in a special way. Each top-level statement in the sortlist\n must itself be an explicit address_match_list with one or two elements. The\n first element (which may be an IP address, an IP prefix, an ACL name, or a nested\n@@ -5895,15 +5895,15 @@\n

\n \n
\n
\n masterfile-format\uf0c1
\n

Grammar: masterfile-format ( raw | text );

\n

Blocks: options, view, zone (mirror, primary, redirect, secondary, stub)

\n-

Tags: server, zone

\n+

Tags: zone, server

\n

Specifies the file format of zone files.

\n

\n

This specifies the file format of zone files (see Additional File Formats\n for details). The default value is text, which is the standard\n textual representation, except for secondary zones, in which the default\n value is raw. Files in formats other than text are typically\n expected to be generated by the named-compilezone tool, or dumped by\n@@ -5971,15 +5971,15 @@\n

\n \n
\n
\n notify-delay\uf0c1
\n

Grammar: notify-delay <integer>;

\n

Blocks: options, view, zone (mirror, primary, secondary)

\n-

Tags: transfer, zone

\n+

Tags: zone, transfer

\n

Sets the delay (in seconds) between sending sets of NOTIFY messages for a zone.

\n

\n

This sets the delay, in seconds, between sending sets of NOTIFY messages\n for a zone. Whenever a NOTIFY message is sent for a zone, a timer will\n be set for this duration. If the zone is updated again before the timer\n expires, the NOTIFY for that update will be postponed. The default is 5\n seconds.

\n@@ -5988,15 +5988,15 @@\n
\n \n
\n
\n max-rsa-exponent-size\uf0c1
\n

Grammar: max-rsa-exponent-size <integer>;

\n

Blocks: options

\n-

Tags: query, dnssec

\n+

Tags: dnssec, query

\n

Sets the maximum RSA exponent size (in bits) when validating.

\n

\n

This sets the maximum RSA exponent size, in bits, that is accepted when\n validating. Valid values are 35 to 4096 bits. The default, zero, is\n also accepted and is equivalent to 4096.

\n
\n \n@@ -6458,15 +6458,15 @@\n deny the existence of domains (NXDOMAIN), deny the existence of IP\n addresses for domains (NODATA), or contain other IP addresses or data.

\n
\n
\n response-policy\uf0c1
\n

Grammar: response-policy { zone <string> [ add-soa <boolean> ] [ log <boolean> ] [ max-policy-ttl <duration> ] [ min-update-interval <duration> ] [ policy ( cname | disabled | drop | given | no-op | nodata | nxdomain | passthru | tcp-only <quoted_string> ) ] [ recursive-only <boolean> ] [ nsip-enable <boolean> ] [ nsdname-enable <boolean> ] [ ede <string> ]; ... } [ add-soa <boolean> ] [ break-dnssec <boolean> ] [ max-policy-ttl <duration> ] [ min-update-interval <duration> ] [ min-ns-dots <integer> ] [ nsip-wait-recurse <boolean> ] [ nsdname-wait-recurse <boolean> ] [ qname-wait-recurse <boolean> ] [ recursive-only <boolean> ] [ nsip-enable <boolean> ] [ nsdname-enable <boolean> ] [ dnsrps-enable <boolean> ] [ dnsrps-options { <unspecified-text> } ];

\n

Blocks: options, view

\n-

Tags: security, query, zone, server

\n+

Tags: zone, query, security, server

\n

Specifies response policy zones for the view or among global options.

\n

\n

Response policy zones are named in the response-policy option for\n the view, or among the global options if there is no response-policy\n option for the view. Response policy zones are ordinary DNS zones\n containing RRsets that can be queried normally if allowed. It is usually\n best to restrict those queries with something like\n@@ -7126,15 +7126,15 @@\n

\n \n
\n
\n log-only\uf0c1
\n

Grammar: log-only <boolean>;

\n

Blocks: options.rate-limit, view.rate-limit

\n-

Tags: query, logging

\n+

Tags: logging, query

\n

Tests rate-limiting parameters without actually dropping any requests.

\n

\n

Use log-only yes to test rate-limiting parameters without actually\n dropping any requests.

\n
\n \n

Responses dropped by rate limits are included in the RateDropped and\n@@ -9751,15 +9751,15 @@\n \n \n

\n
\n server-addresses\uf0c1
\n

Grammar: server-addresses { ( <ipv4_address> | <ipv6_address> ); ... };

\n

Blocks: zone (static-stub)

\n-

Tags: query, zone

\n+

Tags: zone, query

\n

Specifies a list of IP addresses to which queries should be sent in recursive resolution for a static-stub zone.

\n

\n

This option is only meaningful for static-stub zones. This is a list of IP addresses\n to which queries should be sent in recursive resolution for the zone.\n A non-empty list for this option internally configures the apex\n NS RR with associated glue A or AAAA RRs.

\n

For example, if \u201cexample.com\u201d is configured as a static-stub zone\n@@ -10318,15 +10318,15 @@\n

Defines a stream of data that can be independently logged.

\n

\n

logging

\n \n check-dup-records\n

Checks primary zones for records that are treated as different by DNSSEC but are semantically equal in plain DNS.

\n

\n-

query, dnssec

\n+

dnssec, query

\n \n check-integrity\n

Performs post-load zone integrity checks on primary zones.

\n

\n

zone

\n \n check-mx\n@@ -10834,15 +10834,15 @@\n

Sets a maximum size for the memory map of the new-zone database in LMDB database format.

\n

\n

server

\n \n log-only\n

Tests rate-limiting parameters without actually dropping any requests.

\n

\n-

query, logging

\n+

logging, query

\n \n logging\n

Configures logging options for the name server.

\n

\n

logging

\n \n managed-keys\n@@ -10858,15 +10858,15 @@\n

Specifies an access control list (ACL) of IPv4 addresses that are to be mapped to the corresponding A RRset in dns64.

\n

\n

query

\n \n masterfile-format\n

Specifies the file format of zone files.

\n

\n-

server, zone

\n+

zone, server

\n \n masterfile-style\n

Specifies the format of zone files during a dump, when the masterfile-format is text.

\n

\n

server

\n \n match-clients\n@@ -10918,15 +10918,15 @@\n

Specifies the maximum retention time (in seconds) for storage of negative answers in the server's cache.

\n

\n

server

\n \n max-records\n

Sets the maximum number of records permitted in a zone.

\n

\n-

server, zone

\n+

zone, server

\n \n max-recursion-depth\n

Sets the maximum number of levels of recursion permitted at any one time while servicing a recursive query.

\n

\n

server

\n \n max-recursion-queries\n@@ -10943,15 +10943,15 @@\n

Limits the zone refresh retry interval to no less often than the specified value, in seconds.

\n

\n

transfer

\n \n max-rsa-exponent-size\n

Sets the maximum RSA exponent size (in bits) when validating.

\n

\n-

query, dnssec

\n+

dnssec, query

\n \n max-stale-ttl\n

Specifies the maximum time that the server retains records past their normal expiry, to return them as stale records.

\n

\n

server

\n \n max-table-size\n@@ -11078,20 +11078,20 @@\n

Controls whether NOTIFY messages are sent on zone changes.

\n

\n

transfer

\n \n notify-delay\n

Sets the delay (in seconds) between sending sets of NOTIFY messages for a zone.

\n

\n-

transfer, zone

\n+

zone, transfer

\n \n notify-rate\n

Specifies the rate at which NOTIFY requests are sent during normal zone maintenance operations.

\n

\n-

transfer, zone

\n+

zone, transfer

\n \n notify-source\n

Defines the IPv4 address (and optional port) to be used for outgoing NOTIFY messages.

\n

\n

transfer

\n \n notify-source-v6\n@@ -11172,15 +11172,15 @@\n pid-file\n

Specifies the pathname of the file where the server writes its process ID.

\n

\n

server

\n \n pkcs11-uri\n

\n-

pkcs11, dnssec

\n+

dnssec, pkcs11

\n \n plugin\n

Configures plugins in named.conf.

\n

\n

server

\n \n port\n@@ -11342,15 +11342,15 @@\n

Adds an EDNS Padding option to encrypted messages, to reduce the chance of guessing the contents based on size.

\n

\n

query

\n \n response-policy\n

Specifies response policy zones for the view or among global options.

\n

\n-

security, query, zone, server

\n+

zone, query, security, server

\n \n responses-per-second\n

Limits the number of non-empty responses for a valid domain name and record type.

\n

\n

query

\n \n retire-safety\n@@ -11407,15 +11407,15 @@\n

Defines characteristics to be associated with a remote name server.

\n

\n

server

\n \n server-addresses\n

Specifies a list of IP addresses to which queries should be sent in recursive resolution for a static-stub zone.

\n

\n-

query, zone

\n+

zone, query

\n \n server-id\n

Specifies the ID of the server to return in response to a ID.SERVER query.

\n

\n

server

\n \n server-names\n@@ -11496,15 +11496,15 @@\n

Sets the number of "slipped" responses to minimize the use of forged source addresses for an attack.

\n

\n

query

\n \n sortlist\n

Controls the ordering of RRs returned to the client, based on the client's IP address.

\n

\n-

query, deprecated

\n+

deprecated, query

\n \n stale-answer-client-timeout\n

Defines the amount of time (in milliseconds) that named waits before attempting to answer a query with a stale RRset from cache.

\n

\n

query, server

\n \n stale-answer-enable\n@@ -11526,15 +11526,15 @@\n

Sets the time window for the return of "stale" cached answers before the next attempt to contact, if the name servers for a given zone are not responding.

\n

\n

query, server

\n \n startup-notify-rate\n

Specifies the rate at which NOTIFY requests are sent when the name server is first starting, or when new zones have been added.

\n

\n-

transfer, zone

\n+

zone, transfer

\n \n statistics-channels\n

Specifies the communication channels to be used by system administrators to access statistics information on the name server.

\n

\n

logging

\n \n statistics-file\n@@ -11809,35 +11809,35 @@\n

Specifies the length of time during which responses are tracked.

\n

\n

query

\n \n zero-no-soa-ttl\n

Specifies whether to set the time to live (TTL) of the SOA record to zero, when returning authoritative negative responses to SOA queries.

\n

\n-

server, query, zone

\n+

zone, query, server

\n \n zero-no-soa-ttl-cache\n

Sets the time to live (TTL) to zero when caching a negative response to an SOA query.

\n

\n-

server, query, zone

\n+

zone, query, server

\n \n zone\n

Specifies the zone in a BIND 9 configuration.

\n

\n

zone

\n \n zone-propagation-delay\n

Sets the propagation delay from the time a zone is first updated to when the new version of the zone is served by all secondary servers.

\n

\n

dnssec, zone

\n \n zone-statistics\n

Controls the level of statistics gathered for all zones.

\n

\n-

logging, zone

\n+

zone, logging

\n \n \n \n \n
\n

8.4. Statements by Tag\uf0c1

\n

These tables group the various statements permissible in named.conf by\n", "details": [{"source1": "html2text {}", "source2": "html2text {}", "unified_diff": "@@ -515,15 +515,15 @@\n The key-store statement defines how DNSSEC keys should be stored.\n There is one built-in key store named key-directory. Configuring keys to use\n key-store \"key-directory\" is identical to using key-directory.\n The following options can be specified in a _\bk_\be_\by_\b-_\bs_\bt_\bo_\br_\be statement:\n pkcs11-uri_\b\uf0c1\n G\bGr\bra\bam\bmm\bma\bar\br:\b: pkcs11-uri ;\n B\bBl\blo\boc\bck\bks\bs:\b: key-store\n- T\bTa\bag\bgs\bs:\b: pkcs11, dnssec\n+ T\bTa\bag\bgs\bs:\b: dnssec, pkcs11\n The uri is a string that specifies a PKCS#11 URI Scheme (defined in _\bR\bR_\bF\bF_\bC\bC\n _\b7\b7_\b5\b5_\b1\b1_\b2\b2). When set, named will try to create keys inside the corresponding\n PKCS#11 token. This requires BIND to be built with OpenSSL 3, and have a\n PKCS#11 provider configured.\n *\b**\b**\b**\b* 8\b8.\b.2\b2.\b.9\b9.\b. _\bl\bl_\bo\bo_\bg\bg_\bg\bg_\bi\bi_\bn\bn_\bg\bg B\bBl\blo\boc\bck\bk G\bGr\bra\bam\bmm\bma\bar\br_\b?\b\uf0c1 *\b**\b**\b**\b*\n *\b**\b**\b**\b* 8\b8.\b.2\b2.\b.1\b10\b0.\b. _\bl\bl_\bo\bo_\bg\bg_\bg\bg_\bi\bi_\bn\bn_\bg\bg B\bBl\blo\boc\bck\bk D\bDe\bef\bfi\bin\bni\bit\bti\bio\bon\bn a\ban\bnd\bd U\bUs\bsa\bag\bge\be_\b?\b\uf0c1 *\b**\b**\b**\b*\n The _\bl_\bo_\bg_\bg_\bi_\bn_\bg statement configures a wide variety of logging options for the name\n@@ -2500,15 +2500,15 @@\n certificate for a\n connection.\n Defines a stream of data\n _\bc_\bh_\ba_\bn_\bn_\be_\bl that can be independently logging\n logged.\n Checks primary zones for\n records that are treated as\n-_\bc_\bh_\be_\bc_\bk_\b-_\bd_\bu_\bp_\b-_\br_\be_\bc_\bo_\br_\bd_\bs different by DNSSEC but are query, dnssec\n+_\bc_\bh_\be_\bc_\bk_\b-_\bd_\bu_\bp_\b-_\br_\be_\bc_\bo_\br_\bd_\bs different by DNSSEC but are dnssec, query\n semantically equal in plain\n DNS.\n Performs post-load zone\n _\bc_\bh_\be_\bc_\bk_\b-_\bi_\bn_\bt_\be_\bg_\br_\bi_\bt_\by integrity checks on primary zone\n zones.\n Checks whether an MX record\n _\bc_\bh_\be_\bc_\bk_\b-_\bm_\bx appears to refer to an IP zone\n@@ -2824,29 +2824,29 @@\n _\bl_\bi_\bs_\bt_\be_\bn_\be_\br_\b-_\bc_\bl_\bi_\be_\bn_\bt_\bs quota for active query, server\n connections.\n Sets a maximum size for the\n _\bl_\bm_\bd_\bb_\b-_\bm_\ba_\bp_\bs_\bi_\bz_\be memory map of the new-zone server\n database in LMDB database\n format.\n Tests rate-limiting\n-_\bl_\bo_\bg_\b-_\bo_\bn_\bl_\by parameters without actually query, logging\n+_\bl_\bo_\bg_\b-_\bo_\bn_\bl_\by parameters without actually logging, query\n dropping any requests.\n _\bl_\bo_\bg_\bg_\bi_\bn_\bg Configures logging options logging\n for the name server.\n _\bm_\ba_\bn_\ba_\bg_\be_\bd_\b-_\bk_\be_\by_\bs deprecated\n Specifies the directory in\n _\bm_\ba_\bn_\ba_\bg_\be_\bd_\b-_\bk_\be_\by_\bs_\b-_\bd_\bi_\br_\be_\bc_\bt_\bo_\br_\by which to store the files dnssec\n that track managed DNSSEC\n keys.\n Specifies an access control\n list (ACL) of IPv4 addresses\n _\bm_\ba_\bp_\bp_\be_\bd that are to be mapped to the query\n corresponding A RRset in\n _\bd_\bn_\bs_\b6_\b4.\n-_\bm_\ba_\bs_\bt_\be_\br_\bf_\bi_\bl_\be_\b-_\bf_\bo_\br_\bm_\ba_\bt Specifies the file format of server, zone\n+_\bm_\ba_\bs_\bt_\be_\br_\bf_\bi_\bl_\be_\b-_\bf_\bo_\br_\bm_\ba_\bt Specifies the file format of zone, server\n zone files.\n Specifies the format of zone\n _\bm_\ba_\bs_\bt_\be_\br_\bf_\bi_\bl_\be_\b-_\bs_\bt_\by_\bl_\be files during a dump, when server\n the _\bm_\ba_\bs_\bt_\be_\br_\bf_\bi_\bl_\be_\b-_\bf_\bo_\br_\bm_\ba_\bt is\n text.\n Specifies a view of DNS\n _\bm_\ba_\bt_\bc_\bh_\b-_\bc_\bl_\bi_\be_\bn_\bt_\bs namespace for a given subset view\n@@ -2883,15 +2883,15 @@\n _\bm_\ba_\bx_\b-_\bj_\bo_\bu_\br_\bn_\ba_\bl_\b-_\bs_\bi_\bz_\be Controls the size of journal transfer\n files.\n Specifies the maximum\n retention time (in seconds)\n _\bm_\ba_\bx_\b-_\bn_\bc_\ba_\bc_\bh_\be_\b-_\bt_\bt_\bl for storage of negative server\n answers in the server's\n cache.\n-_\bm_\ba_\bx_\b-_\br_\be_\bc_\bo_\br_\bd_\bs Sets the maximum number of server, zone\n+_\bm_\ba_\bx_\b-_\br_\be_\bc_\bo_\br_\bd_\bs Sets the maximum number of zone, server\n records permitted in a zone.\n Sets the maximum number of\n levels of recursion\n _\bm_\ba_\bx_\b-_\br_\be_\bc_\bu_\br_\bs_\bi_\bo_\bn_\b-_\bd_\be_\bp_\bt_\bh permitted at any one time server\n while servicing a recursive\n query.\n Sets the maximum number of\n@@ -2902,15 +2902,15 @@\n than the specified value, in\n seconds.\n Limits the zone refresh\n _\bm_\ba_\bx_\b-_\br_\be_\bt_\br_\by_\b-_\bt_\bi_\bm_\be retry interval to no less transfer\n often than the specified\n value, in seconds.\n Sets the maximum RSA\n-_\bm_\ba_\bx_\b-_\br_\bs_\ba_\b-_\be_\bx_\bp_\bo_\bn_\be_\bn_\bt_\b-_\bs_\bi_\bz_\be exponent size (in bits) when query, dnssec\n+_\bm_\ba_\bx_\b-_\br_\bs_\ba_\b-_\be_\bx_\bp_\bo_\bn_\be_\bn_\bt_\b-_\bs_\bi_\bz_\be exponent size (in bits) when dnssec, query\n validating.\n Specifies the maximum time\n that the server retains\n _\bm_\ba_\bx_\b-_\bs_\bt_\ba_\bl_\be_\b-_\bt_\bt_\bl records past their normal server\n expiry, to return them as\n stale records.\n Sets the maximum size of the\n@@ -3007,18 +3007,18 @@\n Limits the number of empty\n _\bn_\bo_\bd_\ba_\bt_\ba_\b-_\bp_\be_\br_\b-_\bs_\be_\bc_\bo_\bn_\bd (NODATA) responses for a query\n valid domain name.\n Controls whether NOTIFY\n _\bn_\bo_\bt_\bi_\bf_\by messages are sent on zone transfer\n changes.\n Sets the delay (in seconds)\n-_\bn_\bo_\bt_\bi_\bf_\by_\b-_\bd_\be_\bl_\ba_\by between sending sets of transfer, zone\n+_\bn_\bo_\bt_\bi_\bf_\by_\b-_\bd_\be_\bl_\ba_\by between sending sets of zone, transfer\n NOTIFY messages for a zone.\n Specifies the rate at which\n-_\bn_\bo_\bt_\bi_\bf_\by_\b-_\br_\ba_\bt_\be NOTIFY requests are sent transfer, zone\n+_\bn_\bo_\bt_\bi_\bf_\by_\b-_\br_\ba_\bt_\be NOTIFY requests are sent zone, transfer\n during normal zone\n maintenance operations.\n Defines the IPv4 address\n _\bn_\bo_\bt_\bi_\bf_\by_\b-_\bs_\bo_\bu_\br_\bc_\be (and optional port) to be transfer\n used for outgoing NOTIFY\n messages.\n Defines the IPv6 address\n@@ -3072,15 +3072,15 @@\n send parental DS queries.\n Specifies which local IPv6\n _\bp_\ba_\br_\be_\bn_\bt_\ba_\bl_\b-_\bs_\bo_\bu_\br_\bc_\be_\b-_\bv_\b6 source address is used to dnssec\n send parental DS queries.\n Specifies the pathname of\n _\bp_\bi_\bd_\b-_\bf_\bi_\bl_\be the file where the server server\n writes its process ID.\n-_\bp_\bk_\bc_\bs_\b1_\b1_\b-_\bu_\br_\bi pkcs11, dnssec\n+_\bp_\bk_\bc_\bs_\b1_\b1_\b-_\bu_\br_\bi dnssec, pkcs11\n _\bp_\bl_\bu_\bg_\bi_\bn Configures plugins in server\n _\bn_\ba_\bm_\be_\bd_\b._\bc_\bo_\bn_\bf.\n Specifies the UDP/TCP port\n _\bp_\bo_\br_\bt number the server uses to query, server\n receive and send DNS\n protocol traffic.\n Specifies that server\n@@ -3191,15 +3191,15 @@\n _\br_\be_\bs_\bo_\bl_\bv_\be_\br_\b-_\bu_\bs_\be_\b-_\bd_\bn_\bs_\b6_\b4 DNS64 mappings when sending server\n queries.\n Adds an EDNS Padding option\n to encrypted messages, to\n _\br_\be_\bs_\bp_\bo_\bn_\bs_\be_\b-_\bp_\ba_\bd_\bd_\bi_\bn_\bg reduce the chance of query\n guessing the contents based\n on size.\n- Specifies response policy security, query, zone,\n+ Specifies response policy zone, query, security,\n _\br_\be_\bs_\bp_\bo_\bn_\bs_\be_\b-_\bp_\bo_\bl_\bi_\bc_\by zones for the view or among server\n global options.\n Limits the number of non-\n _\br_\be_\bs_\bp_\bo_\bn_\bs_\be_\bs_\b-_\bp_\be_\br_\b-_\bs_\be_\bc_\bo_\bn_\bd empty responses for a valid query\n domain name and record type.\n Increases the amount of time\n a key remains published\n@@ -3238,15 +3238,15 @@\n serial number in the SOA\n record.\n Defines characteristics to\n _\bs_\be_\br_\bv_\be_\br be associated with a remote server\n name server.\n Specifies a list of IP\n addresses to which queries\n-_\bs_\be_\br_\bv_\be_\br_\b-_\ba_\bd_\bd_\br_\be_\bs_\bs_\be_\bs should be sent in recursive query, zone\n+_\bs_\be_\br_\bv_\be_\br_\b-_\ba_\bd_\bd_\br_\be_\bs_\bs_\be_\bs should be sent in recursive zone, query\n resolution for a static-stub\n zone.\n Specifies the ID of the\n _\bs_\be_\br_\bv_\be_\br_\b-_\bi_\bd server to return in response server\n to a ID.SERVER query.\n Specifies a list of domain\n _\bs_\be_\br_\bv_\be_\br_\b-_\bn_\ba_\bm_\be_\bs names of name servers that zone\n@@ -3292,15 +3292,15 @@\n _\bs_\bi_\bg_\bn_\ba_\bt_\bu_\br_\be_\bs_\b-_\bv_\ba_\bl_\bi_\bd_\bi_\bt_\by_\b-_\bd_\bn_\bs_\bk_\be_\by Indicates the validity dnssec\n period of DNSKEY records.\n Sets the number of \"slipped\"\n _\bs_\bl_\bi_\bp responses to minimize the query\n use of forged source\n addresses for an attack.\n Controls the ordering of RRs\n-_\bs_\bo_\br_\bt_\bl_\bi_\bs_\bt returned to the client, query, deprecated\n+_\bs_\bo_\br_\bt_\bl_\bi_\bs_\bt returned to the client, deprecated, query\n based on the client's IP\n address.\n Defines the amount of time\n (in milliseconds) that _\bn_\ba_\bm_\be_\bd\n _\bs_\bt_\ba_\bl_\be_\b-_\ba_\bn_\bs_\bw_\be_\br_\b-_\bc_\bl_\bi_\be_\bn_\bt_\b-_\bt_\bi_\bm_\be_\bo_\bu_\bt waits before attempting to query, server\n answer a query with a stale\n RRset from cache.\n@@ -3317,15 +3317,15 @@\n return of \"stale\" cached\n _\bs_\bt_\ba_\bl_\be_\b-_\br_\be_\bf_\br_\be_\bs_\bh_\b-_\bt_\bi_\bm_\be answers before the next query, server\n attempt to contact, if the\n name servers for a given\n zone are not responding.\n Specifies the rate at which\n NOTIFY requests are sent\n-_\bs_\bt_\ba_\br_\bt_\bu_\bp_\b-_\bn_\bo_\bt_\bi_\bf_\by_\b-_\br_\ba_\bt_\be when the name server is transfer, zone\n+_\bs_\bt_\ba_\br_\bt_\bu_\bp_\b-_\bn_\bo_\bt_\bi_\bf_\by_\b-_\br_\ba_\bt_\be when the name server is zone, transfer\n first starting, or when new\n zones have been added.\n Specifies the communication\n channels to be used by\n _\bs_\bt_\ba_\bt_\bi_\bs_\bt_\bi_\bc_\bs_\b-_\bc_\bh_\ba_\bn_\bn_\be_\bl_\bs system administrators to logging\n access statistics\n information on the name\n@@ -3514,32 +3514,32 @@\n differently depending on who\n is asking.\n Specifies the length of time\n _\bw_\bi_\bn_\bd_\bo_\bw during which responses are query\n tracked.\n Specifies whether to set the\n time to live (TTL) of the\n-_\bz_\be_\br_\bo_\b-_\bn_\bo_\b-_\bs_\bo_\ba_\b-_\bt_\bt_\bl SOA record to zero, when server, query, zone\n+_\bz_\be_\br_\bo_\b-_\bn_\bo_\b-_\bs_\bo_\ba_\b-_\bt_\bt_\bl SOA record to zero, when zone, query, server\n returning authoritative\n negative responses to SOA\n queries.\n Sets the time to live (TTL)\n-_\bz_\be_\br_\bo_\b-_\bn_\bo_\b-_\bs_\bo_\ba_\b-_\bt_\bt_\bl_\b-_\bc_\ba_\bc_\bh_\be to zero when caching a server, query, zone\n+_\bz_\be_\br_\bo_\b-_\bn_\bo_\b-_\bs_\bo_\ba_\b-_\bt_\bt_\bl_\b-_\bc_\ba_\bc_\bh_\be to zero when caching a zone, query, server\n negative response to an SOA\n query.\n _\bz_\bo_\bn_\be Specifies the zone in a BIND zone\n 9 configuration.\n Sets the propagation delay\n from the time a zone is\n _\bz_\bo_\bn_\be_\b-_\bp_\br_\bo_\bp_\ba_\bg_\ba_\bt_\bi_\bo_\bn_\b-_\bd_\be_\bl_\ba_\by first updated to when the dnssec, zone\n new version of the zone is\n served by all secondary\n servers.\n Controls the level of\n-_\bz_\bo_\bn_\be_\b-_\bs_\bt_\ba_\bt_\bi_\bs_\bt_\bi_\bc_\bs statistics gathered for all logging, zone\n+_\bz_\bo_\bn_\be_\b-_\bs_\bt_\ba_\bt_\bi_\bs_\bt_\bi_\bc_\bs statistics gathered for all zone, logging\n zones.\n *\b**\b**\b**\b**\b* 8\b8.\b.4\b4.\b. S\bSt\bta\bat\bte\bem\bme\ben\bnt\bts\bs b\bby\by T\bTa\bag\bg_\b?\b\uf0c1 *\b**\b**\b**\b**\b*\n These tables group the various statements permissible in named.conf by their\n corresponding tag.\n *\b**\b**\b**\b* 8\b8.\b.4\b4.\b.1\b1.\b. D\bDN\bNS\bSS\bSE\bEC\bC T\bTa\bag\bg S\bSt\bta\bat\bte\bem\bme\ben\bnt\bts\bs_\b?\b\uf0c1 *\b**\b**\b**\b*\n S\bSt\bta\bat\bte\bem\bme\ben\bnt\bt D\bDe\bes\bsc\bcr\bri\bip\bpt\bti\bio\bon\bn\n _\bb_\bi_\bn_\bd_\bk_\be_\by_\bs_\b-_\bf_\bi_\bl_\be Specifies the pathname of a file to override the\n"}]}]}]}]}]}