plugin/dnstap: tap deferred error responses (#8549)

When the plugin chain returns an error rcode without writing a response
(it falls off the end, or returns SERVFAIL/REFUSED/FORMERR/NOTIMP), the
server generates and sends the error to the client after dnstap's ServeDNS
returns, so ResponseWriter.WriteMsg is never called and no CLIENT_RESPONSE
dnstap message is emitted. dnstap consumers then see a CLIENT_QUERY with no
matching CLIENT_RESPONSE.

Synthesize the deferred response and tap it as a CLIENT_RESPONSE, mirroring
the deferred-response handling already added to plugin/log.

Fixes #6532

Signed-off-by: Saleh <root@lr0.org>
This commit is contained in:
Saleh
2026-09-15 03:25:11 +03:00
committed by GitHub
parent 22351a0d3c
commit b0b317fdd6
3 changed files with 78 additions and 2 deletions

View File

@@ -16,6 +16,7 @@ type ResponseWriter struct {
queryTime time.Time
query *dns.Msg
ctx context.Context
written bool // whether WriteMsg was called, i.e. a response was written to the client
dns.ResponseWriter
*Dnstap
}
@@ -26,7 +27,14 @@ func (w *ResponseWriter) WriteMsg(resp *dns.Msg) error {
if err != nil {
return err
}
w.written = true
w.tapResponse(resp)
return nil
}
// tapResponse sends a CLIENT_RESPONSE dnstap message for resp. It does not
// write anything back to the client; the caller is responsible for that.
func (w *ResponseWriter) tapResponse(resp *dns.Msg) {
r := new(tap.Message)
msg.SetQueryTime(r, w.queryTime)
msg.SetResponseTime(r, time.Now())
@@ -40,5 +48,4 @@ func (w *ResponseWriter) WriteMsg(resp *dns.Msg) error {
msg.SetType(r, tap.Message_CLIENT_RESPONSE)
state := request.Request{W: w.ResponseWriter, Req: w.query}
w.TapMessageWithMetadata(w.ctx, r, state)
return nil
}