dependabot[bot]
010d8a8485
build(deps): bump github.com/oschwald/geoip2-golang/v2 ( #8560 )
...
Bumps [github.com/oschwald/geoip2-golang/v2](https://github.com/oschwald/geoip2-golang ) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/oschwald/geoip2-golang/releases )
- [Changelog](https://github.com/oschwald/geoip2-golang/blob/main/CHANGELOG.md )
- [Commits](https://github.com/oschwald/geoip2-golang/compare/v2.3.0...v2.4.0 )
---
updated-dependencies:
- dependency-name: github.com/oschwald/geoip2-golang/v2
dependency-version: 2.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 19:08:01 -07:00
Ilya Kulakov
25eb456b57
plugin/file: fix less is not up to RFC 1034 and 4034 ( #8503 )
...
* plugin/file: fix less to follow RFC 1034 and RFC 4034 matching and ordering requirements
- Ensure comparison is left-justified
- Ensure case folding applies only to A-Z
- Decode \DDD without allocations
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: faster exit for less when a == b
Avoid two calls and two reslices.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: consolidate less tests
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: exit less early when there are no more labels
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: match dns.PackDomainName in handling \-escapes
Compare unterminated names as root-terminating
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: More tests of less.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
---------
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
2026-09-16 17:51:15 -07:00
houyuwushang
b93e449b2f
Add opt-in JSON logging with structured DNS query fields ( #8553 )
...
* plugin/pkg/log: add opt-in JSON logging backend
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* plugin/log: emit typed query records in JSON mode
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* coremain: expose process-wide JSON logging
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
---------
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-16 17:50:39 -07:00
houyuwushang
84a93a0b89
plugin/file: reject SOA owners that do not match the zone ( #8555 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-16 17:49:58 -07:00
dependabot[bot]
73198897ef
build(deps): bump golang.org/x/net from 0.58.0 to 0.59.0 ( #8559 )
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.58.0 to 0.59.0.
- [Commits](https://github.com/golang/net/compare/v0.58.0...v0.59.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-version: 0.59.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:49:02 -07:00
dependabot[bot]
78837fa799
build(deps): bump the codeql group with 4 updates ( #8557 )
...
Bumps the codeql group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ), [github/codeql-action/analyze](https://github.com/github/codeql-action ) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ).
Updates `github/codeql-action/init` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
Updates `github/codeql-action/autobuild` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
Updates `github/codeql-action/upload-sarif` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
- dependency-name: github/codeql-action/analyze
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:51 -07:00
dependabot[bot]
c22146e348
build(deps): bump the aws group with 6 updates ( #8558 )
...
Bumps the aws group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.45.1` | `1.46.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.33.2` | `1.33.3` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.20.2` | `1.20.3` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.1` | `1.19.2` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2 ) | `1.68.0` | `1.69.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2 ) | `1.47.0` | `1.48.0` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.45.1 to 1.46.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.45.1...v1.46.0 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.2 to 1.33.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.33.2...config/v1.33.3 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.2 to 1.20.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.20.2...v1.20.3 )
Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.19.1 to 1.19.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.19.1...service/m2/v1.19.2 )
Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.68.0 to 1.69.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.68.0...service/s3/v1.69.0 )
Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.47.0...service/s3/v1.48.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-version: 1.46.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.33.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.20.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
dependency-version: 1.19.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
dependency-version: 1.69.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
dependency-version: 1.48.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:39 -07:00
dependabot[bot]
991401324e
build(deps): bump golang.org/x/crypto from 0.55.0 to 0.57.0 ( #8561 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.55.0 to 0.57.0.
- [Commits](https://github.com/golang/crypto/compare/v0.55.0...v0.57.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-version: 0.57.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:19 -07:00
Ilya Kulakov
1e550ac71a
core/dnsserver: make TsigSecret public ( #8434 )
...
NewServer aggregates secrets from all assigned sites and the final value
can only be reached by plugins via dnsserver.Server
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
2026-09-15 20:02:49 -07:00
Baltasar Blanco
14ed42bd1f
plugin/hosts: don't drop over-long fields silently ( #8551 )
...
#8496 fixed a silent truncation here and named the invariant in its own commit
message: entries were dropped and the hosts file simply looked shorter than it
is, with nothing in the log.
#8516 replaced that mechanism with a streaming parser bounded by maxFieldSize.
The error log #8496 added is still in parse(), but it can no longer report a
dropped entry: bufio.ErrBufferFull is consumed by the read loop, so only a real
I/O error reaches it. A field over maxFieldSize is discarded in lineParser with
no log at all, and when that field is the address the whole line goes with it.
Report both cases, once per dropped field, with the line number and the source
the entries came from.
Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com >
2026-09-15 19:24:23 -07:00
Sakıp Han Dursun
8de7a8b89d
fix(kubernetes): include structured key/value context in client-go logs ( #8490 )
2026-09-15 00:42:44 -07:00
Saleh
b0b317fdd6
plugin/dnstap: tap deferred error responses ( #8549 )
...
When the plugin chain returns an error rcode without writing a response
(it falls off the end, or returns SERVFAIL/REFUSED/FORMERR/NOTIMP), the
server generates and sends the error to the client after dnstap's ServeDNS
returns, so ResponseWriter.WriteMsg is never called and no CLIENT_RESPONSE
dnstap message is emitted. dnstap consumers then see a CLIENT_QUERY with no
matching CLIENT_RESPONSE.
Synthesize the deferred response and tap it as a CLIENT_RESPONSE, mirroring
the deferred-response handling already added to plugin/log.
Fixes #6532
Signed-off-by: Saleh <root@lr0.org >
2026-09-14 17:25:11 -07:00
Paco Cartones
22351a0d3c
fix(metrics): release listener on TLS startup failure ( #8527 )
2026-09-13 17:57:30 -07:00
Ilya Kulakov
5bd1701376
plugin/tls: document that dig supports DoT ( #8539 )
2026-09-13 17:56:16 -07:00
Ilya Kulakov
24abd331e4
fix TestReadme failed cleanup between runs ( #8545 )
...
Instance.Stop does not call shutdown callbacks. Plugins that rely
on them to release resources can leave bound listeners that affect
tests that come next.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
2026-09-12 07:04:41 -07:00
Baltasar Blanco
9221e099e4
docs(corefile): document that the Corefile is line oriented ( #8544 )
...
The Caddyfile parser in coredns/caddy reads the arguments of a plugin, or of one of its properties, up to the end of the line, and a closing brace on that line can be read as one of them. corefile.5.md never said so, and a one-line server block such as '. { whoami }' fails with an error that reads like a brace-matching problem.
Fixes #7267
Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com >
2026-09-11 13:02:05 -07:00
Yong Tang
19adcd8b96
Fix etcd library update issue ( #8542 )
...
This PR fixes etcd library update issue in 8492 where additional lint fix
is needed to take the latest etcd dependency.
This PR supersede 8492.
This PR closes 8492.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-10 23:59:33 -07:00
Yong Tang
6d0a0f222c
Fix DataDog library dependency issue ( #8541 )
...
This PR fixes DataDog library dependency issue where
github.com/DataDog/go-libddwaf/v5 need to be updated to allow DataDog
dependency to compile in arm.
This PR supersede 8533
This PR fixes 8533.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-10 23:19:21 -07:00
houyuwushang
0b376bda5b
test: cover Kubernetes autopath cache refresh ( #8528 )
...
Exercise Pod-dependent search paths through the native Kubernetes plugin during prefetch and stale refresh, including dual-stack resolver results.
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-10 20:55:05 -07:00
houyuwushang
8a269232e4
core/dnsserver: support explicit registration for embedded hosts ( #8525 )
...
* core/dnsserver: test host-plugin embedding with forward
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* core/dnsserver: add a directive setter for embedded hosts
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* core/dnsserver: support explicit server registration for embedded hosts
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
---------
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-10 20:54:41 -07:00
houyuwushang
b51e6d254b
plugin/azure: allow startup with unavailable zones ( #8524 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-10 20:54:12 -07:00
dependabot[bot]
52b85e4c45
build(deps): bump google.golang.org/api from 0.293.0 to 0.297.0 ( #8535 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.293.0 to 0.297.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.293.0...v0.297.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-version: 0.297.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:53:05 -07:00
dependabot[bot]
d5a59d0ba5
build(deps): bump the k8s-io group across 1 directory with 2 updates ( #8491 )
...
Bumps the k8s-io group with 2 updates in the / directory: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery ) and [k8s.io/client-go](https://github.com/kubernetes/client-go ).
Updates `k8s.io/apimachinery` from 0.35.4 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.4...v0.37.0 )
Updates `k8s.io/client-go` from 0.35.4 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md )
- [Commits](https://github.com/kubernetes/client-go/compare/v0.35.4...v0.37.0 )
---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
dependency-version: 0.36.4
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: k8s-io
- dependency-name: k8s.io/client-go
dependency-version: 0.36.4
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: k8s-io
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:31:43 -07:00
dependabot[bot]
70615f3f90
build(deps): bump github.com/quic-go/quic-go from 0.61.0 to 0.62.0 ( #8531 )
...
Bumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go ) from 0.61.0 to 0.62.0.
- [Release notes](https://github.com/quic-go/quic-go/releases )
- [Commits](https://github.com/quic-go/quic-go/compare/v0.61.0...v0.62.0 )
---
updated-dependencies:
- dependency-name: github.com/quic-go/quic-go
dependency-version: 0.62.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:48 -07:00
dependabot[bot]
559336a33f
build(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0 ( #8534 )
...
Bumps [golang.org/x/sys](https://github.com/golang/sys ) from 0.47.0 to 0.48.0.
- [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sys
dependency-version: 0.48.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:39 -07:00
Yong Tang
4382b80a35
core: upgrade Go requirement to 1.26.0 ( #8466 )
...
* core: upgrade Go requirement to 1.26.0
As golang 1.27 has been released, this PR
- Bump Go version requirement to 1.26.0
- Update Go build version to 1.27.0
This is also for solving the issue encountered in 8092 of k8s update
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Bump golang ci
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Migrate faillint to forbidigo, as failint has not bee updated for more than a year
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-10 19:34:44 -07:00
dependabot[bot]
fb7e1d19fd
build(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 ( #8536 )
...
Bumps [github.com/prometheus/client_model](https://github.com/prometheus/client_model ) from 0.6.2 to 0.6.3.
- [Release notes](https://github.com/prometheus/client_model/releases )
- [Commits](https://github.com/prometheus/client_model/compare/v0.6.2...v0.6.3 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/client_model
dependency-version: 0.6.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 18:09:53 -07:00
dependabot[bot]
27540c4f3d
build(deps): bump the aws group with 6 updates ( #8530 )
...
Bumps the aws group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.43.8` | `1.45.1` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.32.39` | `1.33.2` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.38` | `1.20.2` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2 ) | `1.18.39` | `1.19.1` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2 ) | `1.65.10` | `1.68.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2 ) | `1.44.8` | `1.47.0` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.43.8 to 1.45.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.43.8...v1.45.1 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.39 to 1.33.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.39...config/v1.33.2 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.38 to 1.20.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.38...v1.20.2 )
Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.18.39 to 1.19.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/v1.19.1/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.39...v1.19.1 )
Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.65.10 to 1.68.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/fsx/v1.65.10...service/s3/v1.68.0 )
Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.44.8 to 1.47.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/efs/v1.44.8...service/s3/v1.47.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-version: 1.45.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.33.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.20.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
dependency-version: 1.19.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
dependency-version: 1.68.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
dependency-version: 1.47.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:13:28 -07:00
dependabot[bot]
8431d713b7
build(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 ( #8529 )
...
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release ) from 3.0.2 to 3.0.3.
- [Release notes](https://github.com/softprops/action-gh-release/releases )
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md )
- [Commits](3d0d9888cb...efb35369e0 )
---
updated-dependencies:
- dependency-name: softprops/action-gh-release
dependency-version: 3.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:13:14 -07:00
dependabot[bot]
b96ef6ea0a
build(deps): bump github.com/prometheus/common from 0.70.1 to 0.71.0 ( #8532 )
...
Bumps [github.com/prometheus/common](https://github.com/prometheus/common ) from 0.70.1 to 0.71.0.
- [Release notes](https://github.com/prometheus/common/releases )
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prometheus/common/compare/v0.70.1...v0.71.0 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/common
dependency-version: 0.71.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:12:51 -07:00
Paco Cartones
5ac0ca4fad
fix(ready): release lock before server shutdown ( #8526 )
...
Signed-off-by: Paco Cartones <pacocartones@users.noreply.github.com >
Co-authored-by: Paco Cartones <pacocartones@users.noreply.github.com >
2026-09-08 13:15:00 -07:00
Baltasar Blanco
dea2f90f24
plugin/file: return SERVFAIL on self-referential CNAME loops ( #8475 )
...
A CNAME whose target is its own owner name is chased by externalLookup
until the depth cap, appending the same record on every pass. The reply
was NOERROR with the CNAME repeated ten times.
Self-referential DNAME already returns SERVFAIL, as do wildcard CNAME
loops. Return SERVFAIL here too. The check runs on the CNAME chase path
only, so normal responses are unaffected.
Fixes #6421
Signed-off-by: baltasarblanco <baltablanco9008@gmail.com >
2026-09-08 12:21:54 -07:00
houyuwushang
e1d3fe6bc6
plugin/forward: support DNS-over-QUIC upstreams ( #8474 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-07 21:51:18 -07:00
Baltasar Blanco
71a60e140b
plugin/loadbalance: validate the response before dereferencing it in WriteMsg ( #8523 )
2026-09-07 20:50:54 -07:00
sam lockart
9fb1859b23
fix(reload): broadcast shutdown signal ( #8504 )
...
* fix(reload): broadcast shutdown signal
Signed-off-by: alam0rt <sam@samlockart.com >
* fix(reload): scope shutdown state to instances
Signed-off-by: alam0rt <sam@samlockart.com >
---------
Signed-off-by: alam0rt <sam@samlockart.com >
2026-09-06 19:40:07 -07:00
Yash Singh
b24a8b7ddd
Bump golang to 1.26.7 ( #8472 )
...
Signed-off-by: yashsingh74 <yashsingh1774@gmail.com >
2026-09-06 19:21:02 -07:00
myohannes
2b8c305203
plugin/https: Add max_streams to limit HTTP/2 concurrent streams ( #8522 )
...
Add a max_streams option to the *https* plugin to limit the number of
concurrent HTTP/2 streams per DoH connection. This lets operators cap
per-connection concurrency (guarding against resource exhaustion) or
raise it above the Go default for high-fan-in clients that multiplex
many requests over a single connection.
Semantics match the existing *https3* plugin's max_streams:
- omitted -> Go HTTP/2 server default is used
- 0 -> use the underlying HTTP/2 transport default
- positive -> advertise exactly that many concurrent streams
- negative -> rejected at config parse time
The limit is applied via the standard library http.Server.HTTP2
(HTTP2Config.MaxConcurrentStreams) so it is advertised in the server's
SETTINGS frame.
Signed-off-by: Mekias Yohannes <mmyohannes@gmail.com >
2026-09-06 19:16:44 -07:00
Paco Cartones
558c9757a9
plugin/hosts: parse hosts files with bufio.Reader ( #8516 )
2026-09-05 17:39:42 -07:00
Zhao Jianing
b564fcd869
plugin/autopath: Fixes a nil pointer dereference panic in autopath during search path walk ( #8517 )
...
* plugin/autopath: Fixes a nil pointer dereference panic in autopath during search path walk
When a plugin later in the chain returns a ClientWrite rcode without
writing a response (for example acl's drop action, which returns
(dns.RcodeSuccess, nil) without calling WriteMsg), autopath dereferences
a nil nw.Msg at nw.Msg.Rcode and panics. The final fallback
w.WriteMsg(firstReply) can also receive a nil firstReply for the same
reason.
Skip search path elements that produced no message, and only write the
first reply when it is non-nil. This mirrors the nil guards recently
added in plugin/minimal (#8506 ), plugin/dns64 (#8511 ) and plugin/cache
(#8512 ).
Signed-off-by: zjncs <18910855655@163.com >
* plugin/autopath: silence unused-parameter lint and assert no client write
Address review feedback on #8517 : rename the unused 'w' parameter in
TestAutoPathNilMsgFromNext to '_w' so the revive unused-parameter check
passes, and assert that the recorder receives no message so the intended
drop/no-client-write behavior is explicit.
Signed-off-by: zjncs <18910855655@163.com >
---------
Signed-off-by: zjncs <18910855655@163.com >
2026-09-05 02:20:27 -07:00
houyuwushang
b6987aeb4a
request: stop echoing unhandled EDNS options ( #8514 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-04 18:14:53 -07:00
houyuwushang
895eab37e8
plugin/kubernetes: isolate NS address test fixtures ( #8513 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-04 18:14:27 -07:00
Zhao Jianing
99b203f6bb
plugin/k8s_external: Fixes a nil pointer dereference panic when upstream lookup returns no response ( #8518 )
...
* plugin/k8s_external: Fixes a nil pointer dereference panic when upstream lookup returns no response
When a CNAME-hosted service is resolved, k8s_external performs internal
upstream lookups for the target name. Upstream.Lookup can return a nil
message with a nil error when the internal self-query's plugin chain
returns a ClientWrite rcode without writing a response (for example
acl's drop action), and the a/aaaa/srv handlers then dereference
resp.Answer on a nil resp and panic.
Guard all four lookups with err == nil && resp != nil, matching the nil
checks already used in plugin/backend_lookup.go and the guard recently
added to plugin/dns64 (#8511 ).
Signed-off-by: zjncs <18910855655@163.com >
* plugin/k8s_external: silence unused-parameter lint in nil upstream test
The CI lint flagged the test handler's unused 'w' parameter. Rename it
to '_' so golangci-lint (revive unused-parameter) passes. No behavior
change.
Signed-off-by: zjncs <18910855655@163.com >
---------
Signed-off-by: zjncs <18910855655@163.com >
2026-09-04 18:03:47 -07:00
Zhao Jianing
fe9dffcd13
plugin/rewrite: Fixes a nil pointer dereference panic in ResponseReverter.WriteMsg ( #8519 )
...
ResponseReverter.WriteMsg calls res1.Copy() without checking res1 for
nil, so any plugin further down the chain that writes a nil response
(for example a handler returning (dns.RcodeSuccess, nil) after
w.WriteMsg(nil)) panics here.
Return an error instead, mirroring the nil guard recently added to
plugin/cache's ResponseWriter.WriteMsg (#8512 ).
Signed-off-by: zjncs <18910855655@163.com >
2026-09-04 18:02:52 -07:00
Yong Tang
c2e309e2e4
plugin/cache: Prevents a nil pointer dereference panic in the cache prefetch ( #8512 )
...
* plugin/cache: Prevents a nil pointer dereference panic in the cache prefetch
This PR prevents a nil pointer dereference panic in the cache prefetch, by
adding nil guards
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Address comment
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-03 01:11:33 -07:00
Ilya Kulakov
c942ca7c36
plugin: use Zones.Contains when any match suffices ( #8505 )
2026-09-02 23:59:58 -07:00
Yong Tang
f1d835aa51
plugin/dns64: Fixes a nil pointer dereference panic in dns64 during response ( #8511 )
...
This PR fixes a nil pointer dereference panic in dns64 during response,
when the internal A-record upstream re-lookup returns a nil response.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-02 21:07:28 -07:00
Yong Tang
88ab058ba2
plugin/minimal: Fixes a nil pointer dereference panic in minimal prefetch response processing ( #8506 )
...
* plugin/minimal: Fixes a nil pointer dereference panic in minimal prefetch response processing
This PR fixes a nil pointer dereference panic in minimal prefetch response processing
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix lint
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-02 07:58:49 -07:00
dependabot[bot]
a87f9efcc5
build(deps): bump github.com/prometheus/exporter-toolkit ( #8510 )
...
Bumps [github.com/prometheus/exporter-toolkit](https://github.com/prometheus/exporter-toolkit ) from 0.18.0 to 0.19.0.
- [Release notes](https://github.com/prometheus/exporter-toolkit/releases )
- [Commits](https://github.com/prometheus/exporter-toolkit/compare/v0.18.0...v0.19.0 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/exporter-toolkit
dependency-version: 0.19.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 07:04:25 -07:00
dependabot[bot]
b8060a1e80
build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 ( #8509 )
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.83.1 to 1.83.2.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.83.1...v1.83.2 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-version: 1.83.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 07:04:09 -07:00
dependabot[bot]
947bc75578
build(deps): bump the aws group with 6 updates ( #8508 )
...
Bumps the aws group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.43.7` | `1.43.8` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.32.38` | `1.32.39` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.37` | `1.19.38` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2 ) | `1.18.38` | `1.18.39` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2 ) | `1.65.9` | `1.65.10` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2 ) | `1.44.7` | `1.44.8` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.43.7 to 1.43.8
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.43.7...v1.43.8 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.38 to 1.32.39
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.38...config/v1.32.39 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.37 to 1.19.38
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.37...credentials/v1.19.38 )
Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.18.38 to 1.18.39
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.38...config/v1.18.39 )
Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.65.9 to 1.65.10
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/fsx/v1.65.9...service/fsx/v1.65.10 )
Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.44.7 to 1.44.8
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ssm/v1.44.7...service/efs/v1.44.8 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-version: 1.43.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.32.39
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.19.38
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
dependency-version: 1.18.39
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
dependency-version: 1.65.10
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
dependency-version: 1.44.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 07:03:45 -07:00