diff --git a/plugin/cache/cache.go b/plugin/cache/cache.go index 8cb49dceb..149fc5803 100644 --- a/plugin/cache/cache.go +++ b/plugin/cache/cache.go @@ -91,6 +91,13 @@ func key(qname string, m *dns.Msg, t response.Type, do, cd bool) (bool, uint64) if m.Truncated { return false, 0 } + // A response with no question cannot be keyed or cached and would panic + // on m.Question[0] below. Some plugins can emit such a malformed message + // (e.g. during prefetch); warn and skip it rather than crash the server. + if len(m.Question) == 0 { + log.Warningf("Not caching malformed response with an empty question section for %q", qname) + return false, 0 + } // Nor errors or Meta or Update. if t == response.OtherError || t == response.Meta || t == response.Update { return false, 0 diff --git a/plugin/cache/cache_test.go b/plugin/cache/cache_test.go index 0fbaf390b..7065f1636 100644 --- a/plugin/cache/cache_test.go +++ b/plugin/cache/cache_test.go @@ -2008,3 +2008,16 @@ func TestCacheWriteMsgNilResponse(t *testing.T) { t.Error("Expected error when passing nil response to WriteMsg, got nil") } } + +func TestKeyEmptyQuestion(t *testing.T) { + // A response with an empty question section must be reported as + // non-cacheable instead of panicking on m.Question[0]. Some plugins can + // emit such a message (e.g. during prefetch). Regression test for #6051. + m := new(dns.Msg) + m.Response = true + m.Rcode = dns.RcodeSuccess + + if ok, _ := key("example.org.", m, response.NoError, false, false); ok { + t.Fatal("expected a response with an empty question section to be non-cacheable") + } +}