plugin/cache: don't cache or panic on responses with no question (#8467)

An upstream may return a NOERROR message with an empty question section
(some plugins emit this during prefetch). response.Typify classifies it
as NoError, so key falls through to m.Question[0] and panics, taking
down the server. Skip caching such a malformed response and log a
warning instead.

Fixes #6051

Signed-off-by: Saleh <root@lr0.org>
This commit is contained in:
Saleh
2026-09-19 02:56:04 +03:00
committed by GitHub
parent 010d8a8485
commit 8f2d1cb7f4
2 changed files with 20 additions and 0 deletions

View File

@@ -91,6 +91,13 @@ func key(qname string, m *dns.Msg, t response.Type, do, cd bool) (bool, uint64)
if m.Truncated {
return false, 0
}
// A response with no question cannot be keyed or cached and would panic
// on m.Question[0] below. Some plugins can emit such a malformed message
// (e.g. during prefetch); warn and skip it rather than crash the server.
if len(m.Question) == 0 {
log.Warningf("Not caching malformed response with an empty question section for %q", qname)
return false, 0
}
// Nor errors or Meta or Update.
if t == response.OtherError || t == response.Meta || t == response.Update {
return false, 0