plugin/cache: don't cache or panic on responses with no question (#8467)

An upstream may return a NOERROR message with an empty question section
(some plugins emit this during prefetch). response.Typify classifies it
as NoError, so key falls through to m.Question[0] and panics, taking
down the server. Skip caching such a malformed response and log a
warning instead.

Fixes #6051

Signed-off-by: Saleh <root@lr0.org>
This commit is contained in:
Saleh
2026-09-19 02:56:04 +03:00
committed by GitHub
parent 010d8a8485
commit 8f2d1cb7f4
2 changed files with 20 additions and 0 deletions

View File

@@ -2008,3 +2008,16 @@ func TestCacheWriteMsgNilResponse(t *testing.T) {
t.Error("Expected error when passing nil response to WriteMsg, got nil")
}
}
func TestKeyEmptyQuestion(t *testing.T) {
// A response with an empty question section must be reported as
// non-cacheable instead of panicking on m.Question[0]. Some plugins can
// emit such a message (e.g. during prefetch). Regression test for #6051.
m := new(dns.Msg)
m.Response = true
m.Rcode = dns.RcodeSuccess
if ok, _ := key("example.org.", m, response.NoError, false, false); ok {
t.Fatal("expected a response with an empty question section to be non-cacheable")
}
}