aboutsummaryrefslogtreecommitdiff
path: root/assets/easyeffects-eq-presets.org
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-08-19 12:32:07 -0700
committerCraig Jennings <c@cjennings.net>2026-08-19 12:32:07 -0700
commit7b68f77a9b99e5400472986cb80bae5fb92e2320 (patch)
treec9beef06a73bd6b107753c1e8e3e6350ad290aad /assets/easyeffects-eq-presets.org
parentec3a63caca4f2d955e594318a9a690e4c28af19e (diff)
downloadarchsetup-7b68f77a9b99e5400472986cb80bae5fb92e2320.tar.gz
archsetup-7b68f77a9b99e5400472986cb80bae5fb92e2320.zip
docs: correct the clock/DNS deadlock mechanism to DNSSEC
I reproduced the failure by winding velox's clock back 27 days with chronyd stopped, and the cause is not what I recorded. Resolved logged signature-expired against the root DNSKEY and every DS beneath it. The DoT handshake to 1.1.1.1:853 verified clean at that same clock, and the Cloudflare certificate runs Dec 2025 to Dec 2026, so it was never outside its window. An RRSIG window is days to weeks while a certificate is good for a year, so a skew that breaks DNSSEC normally leaves DoT untouched. DNSSEC=allow-downgrade does not rescue it either. Resolved downgrades when a server lacks DNSSEC support, and a signature-window failure is a validation failure, so no downgrade fires. Six retries over eighteen seconds plus a reset-server-features, all dead. I briefly believed otherwise off a test whose success was a cache hit. The fix itself is verified end to end. With the clock wound back and no DNS at all, chronyd reached the IP-addressed source and stepped the clock straight back. Also settled: the clock landed on 2026-07-23 because that is systemd 261.2's build date to the minute, and systemd advances a garbage RTC to its own build epoch at boot.
Diffstat (limited to 'assets/easyeffects-eq-presets.org')
0 files changed, 0 insertions, 0 deletions