mirror of
https://github.com/coredns/coredns.git
synced 2026-10-09 03:55:21 -04:00
plugin/loadbalance: validate the response before dereferencing it in WriteMsg (#8523)
This commit is contained in:
@@ -1,6 +1,8 @@
|
||||
package loadbalance
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/miekg/dns"
|
||||
)
|
||||
|
||||
@@ -17,10 +19,21 @@ type LoadBalanceResponseWriter struct {
|
||||
|
||||
// WriteMsg implements the dns.ResponseWriter interface.
|
||||
func (r *LoadBalanceResponseWriter) WriteMsg(res *dns.Msg) error {
|
||||
if res == nil {
|
||||
return fmt.Errorf("loadbalance: response message is nil")
|
||||
}
|
||||
|
||||
if res.Rcode != dns.RcodeSuccess {
|
||||
return r.ResponseWriter.WriteMsg(res)
|
||||
}
|
||||
|
||||
// A response can arrive with no question section at all, in which case
|
||||
// there is nothing to key the shuffle on and Question[0] below would
|
||||
// panic. Pass it through untouched, as the transfer types do.
|
||||
if len(res.Question) == 0 {
|
||||
return r.ResponseWriter.WriteMsg(res)
|
||||
}
|
||||
|
||||
if res.Question[0].Qtype == dns.TypeAXFR || res.Question[0].Qtype == dns.TypeIXFR {
|
||||
return r.ResponseWriter.WriteMsg(res)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user