request: stop echoing unhandled EDNS options (#8514)

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
This commit is contained in:
houyuwushang
2026-09-05 09:14:53 +08:00
committed by GitHub
parent 895eab37e8
commit b6987aeb4a
6 changed files with 77 additions and 64 deletions

View File

@@ -15,18 +15,15 @@ type supported struct {
sync.RWMutex
}
// SetSupportedOption adds a new supported option the set of EDNS0 options that we support. Plugins typically call
// this in their setup code to signal support for a new option.
// By default we support:
// dns.EDNS0NSID, dns.EDNS0EXPIRE, dns.EDNS0COOKIE, dns.EDNS0TCPKEEPALIVE, dns.EDNS0PADDING. These
// values are not in this map and checked directly in the server.
// SetSupportedOption adds an EDNS0 option to the set of options that CoreDNS may copy from a request to an
// OPT-less response. Plugins typically call this in their setup code to signal support for a custom option.
func SetSupportedOption(option uint16) {
sup.Lock()
sup.m[option] = struct{}{}
sup.Unlock()
}
// SupportedOption returns true if the option code is supported as an extra EDNS0 option.
// SupportedOption returns true if the option code was explicitly registered.
func SupportedOption(option uint16) bool {
sup.RLock()
_, ok := sup.m[option]

View File

@@ -1193,16 +1193,12 @@ func TestRewriteEDNS0RevertDoesNotLeakThroughScrubWriter(t *testing.T) {
if o == nil {
t.Fatal("expected EDNS0 option record in response")
}
var foundCookie bool
for _, opt := range o.Option {
if opt.Option() == 0xffee {
t.Fatalf("expected rewritten EDNS0 option to be reverted, got %v", o.Option)
}
if opt.Option() == dns.EDNS0COOKIE {
foundCookie = true
t.Fatalf("expected request EDNS0 cookie option not to be copied to the response, got %v", o.Option)
}
}
if !foundCookie {
t.Fatalf("expected original EDNS0 cookie option to be preserved, got %v", o.Option)
}
}