With EDNS client subnet support enabled, unbound will add client IP address
to requests. This could lead to an unexpected IP address leak. Therefore
we hide that feature behind a USE flag (ecs) and let user decide.
Package-Manager: Portage-2.3.49, Repoman-2.3.10
<flag name="dnscrypt">Enable DNSCrypt support</flag>
<flag name="dnstap">Enable dnstap support</flag>
<flag name="ecdsa">Enable ECDSA support</flag>
+ <flag name="ecs">Enable EDNS client subnet support</flag>
<flag name="gost">Enable GOST support</flag>
<flag name="redis">Enable cache db backend which uses <pkg>dev-libs/hiredis</pkg></flag>
</use>
LICENSE="BSD GPL-2"
SLOT="0/8" # ABI version of libunbound.so
KEYWORDS="~alpha ~amd64 ~arm ~hppa ~mips ~ppc ~ppc64 ~x86"
-IUSE="debug dnscrypt dnstap +ecdsa gost libressl python redis selinux static-libs systemd test threads"
+IUSE="debug dnscrypt dnstap +ecdsa ecs gost libressl python redis selinux static-libs systemd test threads"
REQUIRED_USE="python? ( ${PYTHON_REQUIRED_USE} )"
# Note: expat is needed by executable only but the Makefile is custom
$(use_enable dnscrypt) \
$(use_enable dnstap) \
$(use_enable ecdsa) \
+ $(use_enable ecs subnet) \
$(multilib_native_use_enable redis cachedb) \
$(use_enable static-libs static) \
$(use_enable systemd) \
--disable-flto \
--disable-rpath \
--enable-ipsecmod \
- --enable-subnet \
--enable-tfo-client \
--enable-tfo-server \
--with-libevent="${EPREFIX%/}"/usr \