core: Reject conflicting TLS policies on shared listeners. (#8565)

* core: Reject conflicting TLS policies on shared listeners.

This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix ACME

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
This commit is contained in:
Yong Tang
2026-09-21 23:56:27 -07:00
committed by GitHub
parent 559e57ec55
commit 8d66643935
12 changed files with 308 additions and 47 deletions

View File

@@ -70,6 +70,10 @@ type Config struct {
// TLSConfig when listening for encrypted connections (gRPC, DNS-over-TLS).
TLSConfig *tls.Config
// tlsConfigIdentity identifies dynamic TLS configurations that are known to
// represent the same listener-wide policy even after tls.Config.Clone.
tlsConfigIdentity *TLSConfigIdentity
// MaxQUICStreams defines the maximum number of concurrent QUIC streams for a QUIC server.
// This is nil if not specified, allowing for a default to be used.
MaxQUICStreams *int
@@ -165,6 +169,22 @@ type Config struct {
// FilterFunc is a function that filters requests from the Config
type FilterFunc func(context.Context, *request.Request) bool
// TLSConfigIdentity is an opaque identity for equivalent dynamic TLS policies.
// Plugins should share one identity only when they can prove that independently
// constructed TLS configs are interchangeable on the same listener.
type TLSConfigIdentity struct {
_ byte
}
// NewTLSConfigIdentity returns a new opaque TLS policy identity.
func NewTLSConfigIdentity() *TLSConfigIdentity { return &TLSConfigIdentity{} }
// SetTLSConfigIdentity associates an opaque listener-wide policy identity with
// this config.
func (c *Config) SetTLSConfigIdentity(identity *TLSConfigIdentity) {
c.tlsConfigIdentity = identity
}
// keyForConfig builds a key for identifying the configs during setup time
func keyForConfig(blocIndex int, blocKeyIndex int) string {
return fmt.Sprintf("%d:%d", blocIndex, blocKeyIndex)