plugin/dynupdate: add durable authenticated RFC 2136 updates (#8520)

* plugin/dynupdate: add authenticated RFC 2136 updates

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: fix README test fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* test: format README fixture map

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: persist updates and bound writable zones

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: preserve middleware and fix interoperability fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* test(dynupdate): validate Kea lifecycle and bounded zone costs

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: reject duplicate directives and harden client fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: fix update routing and startup validation

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

---------

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
This commit is contained in:
houyuwushang
2026-09-22 15:53:26 +08:00
committed by GitHub
parent 8d66643935
commit 5aa4dc2941
24 changed files with 4326 additions and 1 deletions

View File

@@ -54,6 +54,7 @@ type Cache struct {
// Positive/negative zone exceptions
pexcept []string
nexcept []string
bypass []string // mutable authoritative zones discovered at startup
// Keep ttl option
keepttl bool
@@ -62,6 +63,12 @@ type Cache struct {
now func() time.Time
}
// ZoneBypasser identifies canonical authoritative zones that must always be
// queried directly. Cache discovers implementations in its server block at startup.
type ZoneBypasser interface {
CacheBypassZones() []string
}
// New returns an initialized Cache with default settings. It's up to the
// caller to set the Next handler.
func New() *Cache {

View File

@@ -15,13 +15,20 @@ import (
// ServeDNS implements the plugin.Handler interface.
func (c *Cache) ServeDNS(ctx context.Context, w dns.ResponseWriter, r *dns.Msg) (int, error) {
// The cache only handles QUERY messages. In particular, an UPDATE can
// have the same zone name and QTYPE as a cached query, but must always
// reach the authoritative handler instead of being answered from cache.
if r.Opcode != dns.OpcodeQuery {
return plugin.NextOrFailure(c.Name(), c.Next, ctx, w, r)
}
rc := r.Copy() // We potentially modify r, to prevent other plugins from seeing this (r is a pointer), copy r into rc.
state := request.Request{W: w, Req: rc}
do := state.Do()
cd := r.CheckingDisabled
ad := r.AuthenticatedData
if !plugin.Zones(c.Zones).Contains(state.Name()) {
if !plugin.Zones(c.Zones).Contains(state.Name()) || plugin.Zones(c.bypass).Contains(state.Name()) {
return plugin.NextOrFailure(c.Name(), c.Next, ctx, w, rc)
}

77
plugin/cache/non_query_test.go vendored Normal file
View File

@@ -0,0 +1,77 @@
package cache
import (
"context"
"testing"
"github.com/coredns/coredns/plugin"
"github.com/coredns/coredns/plugin/pkg/dnstest"
"github.com/coredns/coredns/plugin/test"
"github.com/miekg/dns"
)
func TestCachePassesNonQueryToNext(t *testing.T) {
c := New()
called := false
c.Next = plugin.HandlerFunc(func(_ context.Context, w dns.ResponseWriter, r *dns.Msg) (int, error) {
called = true
if r.Opcode != dns.OpcodeUpdate {
t.Errorf("next handler received opcode %d, want UPDATE", r.Opcode)
}
m := new(dns.Msg).SetReply(r)
if err := w.WriteMsg(m); err != nil {
return dns.RcodeServerFailure, err
}
return dns.RcodeSuccess, nil
})
r := new(dns.Msg).SetUpdate("example.org.")
w := dnstest.NewRecorder(&test.ResponseWriter{})
code, err := c.ServeDNS(context.Background(), w, r)
if err != nil || code != dns.RcodeSuccess {
t.Fatalf("ServeDNS returned code=%d err=%v", code, err)
}
if !called {
t.Fatal("non-QUERY message did not reach the next handler")
}
if w.Msg == nil || w.Msg.Opcode != dns.OpcodeUpdate {
t.Fatalf("response = %#v, want an UPDATE response", w.Msg)
}
}
func TestCacheBypassesMutableZones(t *testing.T) {
c := New()
calls := 0
c.Next = plugin.HandlerFunc(func(_ context.Context, w dns.ResponseWriter, r *dns.Msg) (int, error) {
calls++
m := new(dns.Msg).SetReply(r)
rr, err := dns.NewRR(r.Question[0].Name + " 60 IN A 192.0.2.1")
if err != nil {
return dns.RcodeServerFailure, err
}
m.Answer = []dns.RR{rr}
return dns.RcodeSuccess, w.WriteMsg(m)
})
query := func(name string) {
t.Helper()
r := new(dns.Msg)
r.SetQuestion(name, dns.TypeA)
w := dnstest.NewRecorder(&test.ResponseWriter{})
if code, err := c.ServeDNS(context.Background(), w, r); code != dns.RcodeSuccess || err != nil {
t.Fatalf("query: %d %v", code, err)
}
}
query("mutable.example.org.")
c.bypass = []string{"example.org."}
query("mutable.example.org.")
query("mutable.example.org.")
if calls != 3 {
t.Fatalf("mutable queries used cache: %d upstream calls", calls)
}
query("static.example.net.")
query("static.example.net.")
if calls != 4 {
t.Fatalf("unrelated zone was not cached: %d upstream calls", calls)
}
}

View File

@@ -26,6 +26,11 @@ func setup(c *caddy.Controller) error {
c.OnStartup(func() error {
ca.viewMetricLabel = dnsserver.GetConfig(c).ViewName
for _, h := range dnsserver.GetConfig(c).Handlers() {
if b, ok := h.(ZoneBypasser); ok {
ca.bypass = append(ca.bypass, b.CacheBypassZones()...)
}
}
return nil
})