plugin/dns64: reject unsupported prefix lengths (#8611)

This commit is contained in:
jxj
2026-10-08 16:25:27 +08:00
committed by GitHub
parent 311a9915da
commit e886525620
3 changed files with 25 additions and 1 deletions

View File

@@ -20,6 +20,8 @@ dns64 [PREFIX]
~~~
* **PREFIX** defines a custom prefix instead of the default `64:ff9b::/96`.
Its length must be 32, 40, 48, 56, 64, or 96 bits, as defined in
[RFC 6052 Section 2.2](https://www.rfc-editor.org/info/rfc6052/#section-2.2).
Or use this slightly longer form with more options:

View File

@@ -84,7 +84,9 @@ func parsePrefix(c *caddy.Controller, addr string) (*net.IPNet, error) {
if total != 128 {
return nil, c.Errf("invalid netmask %d IPv6 address: %q", total, pref)
}
if n%8 != 0 || n < 32 || n > 96 {
switch n {
case 32, 40, 48, 56, 64, 96:
default:
return nil, c.Errf("invalid prefix length %q", pref)
}

View File

@@ -1,11 +1,31 @@
package dns64
import (
"fmt"
"testing"
"github.com/coredns/caddy"
)
func TestSetupDns64PrefixLengths(t *testing.T) {
for _, length := range []int{32, 40, 48, 56, 64, 72, 80, 88, 96} {
prefix := fmt.Sprintf("2001:db8::/%d", length)
for _, input := range []string{
"dns64 " + prefix,
"dns64 {\n prefix " + prefix + "\n}",
} {
t.Run(input, func(t *testing.T) {
c := caddy.NewTestController("dns", input)
_, err := dns64Parse(c)
invalid := length == 72 || length == 80 || length == 88
if (err != nil) != invalid {
t.Errorf("prefix /%d: expected error %v, got %v", length, invalid, err)
}
})
}
}
}
func TestSetupDns64(t *testing.T) {
tests := []struct {
inputUpstreams string