llucas
0e9d7f4d05
plugin/forward ensure forward sets the DOH host ( #8470 )
...
* ensure forward sets the DOH host
Signed-off-by: ccie57654 <ccie57654@proton.me >
* added DoHHost value test
Signed-off-by: ccie57654 <ccie57654@proton.me >
---------
Signed-off-by: ccie57654 <ccie57654@proton.me >
2026-09-28 05:40:16 -07:00
jxj
72160e6e20
plugin/file: track zone mtime for reload_by_mtime ( #8556 )
...
* plugin/file: track zone mtime for reload_by_mtime
Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com >
* plugin/file: capture initial mtime before parsing
Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com >
* plugin/file: keep unloaded zones retryable after open error
Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com >
---------
Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com >
2026-09-28 00:22:39 -07:00
github-actions[bot]
6755e6276d
auto make -f Makefile.doc ( #8578 )
...
Signed-off-by: coredns[bot] <bot@coredns.io >
Co-authored-by: coredns[bot] <bot@coredns.io >
2026-09-27 19:00:04 -07:00
Arunesh Dwivedi
f781f97334
fix: return error from zipkin NewEndpoint in trace setup ( #8577 )
2026-09-27 16:35:03 -07:00
Amila Senadheera
95484f76ed
rewrite/cname: point to config instead of copying ( #8568 )
...
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com >
2026-09-23 17:02:02 -07:00
dependabot[bot]
6cb01361d7
build(deps): bump google.golang.org/api from 0.297.0 to 0.298.0 ( #8574 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.297.0 to 0.298.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.297.0...v0.298.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-version: 0.298.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-23 17:01:00 -07:00
dependabot[bot]
73c1c17738
build(deps): bump the aws group with 6 updates ( #8573 )
...
Bumps the aws group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.46.0` | `1.47.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.33.3` | `1.33.5` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.20.3` | `1.20.5` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.2` | `1.20.0` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2 ) | `1.69.0` | `1.70.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2 ) | `1.48.0` | `1.50.0` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.46.0...v1.47.0 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.3 to 1.33.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.33.3...config/v1.33.5 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.3 to 1.20.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.20.3...service/mq/v1.20.5 )
Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.19.2 to 1.20.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/v1.20.0/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/m2/v1.19.2...v1.20.0 )
Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.69.0 to 1.70.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.69.0...service/s3/v1.70.0 )
Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.48.0 to 1.50.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.48.0...service/s3/v1.50.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-version: 1.47.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.33.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.20.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
dependency-version: 1.20.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
dependency-version: 1.70.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
dependency-version: 1.50.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-23 17:00:51 -07:00
dependabot[bot]
34f6827f4c
build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 ( #8572 )
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 10.0.1 to 10.1.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](20cfd1bf94...bec219d24c )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 10.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-23 17:00:38 -07:00
Ilya Kulakov
615e3d4e11
deps: bump caddy to v1.1.4 ( #8562 )
...
v1.1.4 has important fixes for parsing nested blocks.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
2026-09-22 19:08:09 -07:00
Yong Tang
d5c1188843
plugin/rewrite: Limit rewrite cname recursion ( #8570 )
...
This PR limit rewrite cname recursion with the existing DNS server loop counter.
The issu was that rewrite cname can recurse indefinitely through internal lookups, causing crash at the end
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-22 06:23:20 -07:00
houyuwushang
5aa4dc2941
plugin/dynupdate: add durable authenticated RFC 2136 updates ( #8520 )
...
* plugin/dynupdate: add authenticated RFC 2136 updates
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* plugin/dynupdate: fix README test fixtures
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* test: format README fixture map
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* plugin/dynupdate: persist updates and bound writable zones
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* plugin/dynupdate: preserve middleware and fix interoperability fixtures
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* test(dynupdate): validate Kea lifecycle and bounded zone costs
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* plugin/dynupdate: reject duplicate directives and harden client fixtures
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* plugin/dynupdate: fix update routing and startup validation
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
---------
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-22 00:53:26 -07:00
Yong Tang
8d66643935
core: Reject conflicting TLS policies on shared listeners. ( #8565 )
...
* core: Reject conflicting TLS policies on shared listeners.
This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix ACME
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-21 23:56:27 -07:00
Amila Senadheera
559e57ec55
DoQ: cancel only the stalled stream, not the whole DoQ connection ( #8567 )
...
* DoQ: cancel only the stalled stream, not the whole DoQ connection
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com >
* sent only RESET_STREAM, STOP_SENDING is for client cancelling stream
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com >
---------
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com >
2026-09-21 12:49:37 -07:00
Yong Tang
5cb7cdc914
plugin/forward: Treat forward upstream hostnames as absolute FQDNs to avoid search-domain resolution. ( #8563 )
2026-09-19 21:37:34 -07:00
houyuwushang
ce5ee05bee
plugin/forward: bound DoT connection setup for retries ( #8543 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-18 16:56:31 -07:00
Saleh
8f2d1cb7f4
plugin/cache: don't cache or panic on responses with no question ( #8467 )
...
An upstream may return a NOERROR message with an empty question section
(some plugins emit this during prefetch). response.Typify classifies it
as NoError, so key falls through to m.Question[0] and panics, taking
down the server. Skip caching such a malformed response and log a
warning instead.
Fixes #6051
Signed-off-by: Saleh <root@lr0.org >
2026-09-18 16:56:04 -07:00
dependabot[bot]
010d8a8485
build(deps): bump github.com/oschwald/geoip2-golang/v2 ( #8560 )
...
Bumps [github.com/oschwald/geoip2-golang/v2](https://github.com/oschwald/geoip2-golang ) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/oschwald/geoip2-golang/releases )
- [Changelog](https://github.com/oschwald/geoip2-golang/blob/main/CHANGELOG.md )
- [Commits](https://github.com/oschwald/geoip2-golang/compare/v2.3.0...v2.4.0 )
---
updated-dependencies:
- dependency-name: github.com/oschwald/geoip2-golang/v2
dependency-version: 2.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 19:08:01 -07:00
Ilya Kulakov
25eb456b57
plugin/file: fix less is not up to RFC 1034 and 4034 ( #8503 )
...
* plugin/file: fix less to follow RFC 1034 and RFC 4034 matching and ordering requirements
- Ensure comparison is left-justified
- Ensure case folding applies only to A-Z
- Decode \DDD without allocations
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: faster exit for less when a == b
Avoid two calls and two reslices.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: consolidate less tests
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: exit less early when there are no more labels
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: match dns.PackDomainName in handling \-escapes
Compare unterminated names as root-terminating
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
* plugin/file: More tests of less.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
---------
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
2026-09-16 17:51:15 -07:00
houyuwushang
b93e449b2f
Add opt-in JSON logging with structured DNS query fields ( #8553 )
...
* plugin/pkg/log: add opt-in JSON logging backend
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* plugin/log: emit typed query records in JSON mode
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* coremain: expose process-wide JSON logging
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
---------
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-16 17:50:39 -07:00
houyuwushang
84a93a0b89
plugin/file: reject SOA owners that do not match the zone ( #8555 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-16 17:49:58 -07:00
dependabot[bot]
73198897ef
build(deps): bump golang.org/x/net from 0.58.0 to 0.59.0 ( #8559 )
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.58.0 to 0.59.0.
- [Commits](https://github.com/golang/net/compare/v0.58.0...v0.59.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-version: 0.59.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:49:02 -07:00
dependabot[bot]
78837fa799
build(deps): bump the codeql group with 4 updates ( #8557 )
...
Bumps the codeql group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ), [github/codeql-action/analyze](https://github.com/github/codeql-action ) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ).
Updates `github/codeql-action/init` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
Updates `github/codeql-action/autobuild` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
Updates `github/codeql-action/upload-sarif` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](cdf488f595...b96794f015 )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
- dependency-name: github/codeql-action/analyze
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:51 -07:00
dependabot[bot]
c22146e348
build(deps): bump the aws group with 6 updates ( #8558 )
...
Bumps the aws group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.45.1` | `1.46.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.33.2` | `1.33.3` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.20.2` | `1.20.3` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.1` | `1.19.2` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2 ) | `1.68.0` | `1.69.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2 ) | `1.47.0` | `1.48.0` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.45.1 to 1.46.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.45.1...v1.46.0 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.2 to 1.33.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.33.2...config/v1.33.3 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.2 to 1.20.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.20.2...v1.20.3 )
Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.19.1 to 1.19.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.19.1...service/m2/v1.19.2 )
Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.68.0 to 1.69.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.68.0...service/s3/v1.69.0 )
Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.47.0...service/s3/v1.48.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-version: 1.46.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.33.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.20.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
dependency-version: 1.19.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
dependency-version: 1.69.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
dependency-version: 1.48.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:39 -07:00
dependabot[bot]
991401324e
build(deps): bump golang.org/x/crypto from 0.55.0 to 0.57.0 ( #8561 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.55.0 to 0.57.0.
- [Commits](https://github.com/golang/crypto/compare/v0.55.0...v0.57.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-version: 0.57.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:19 -07:00
Ilya Kulakov
1e550ac71a
core/dnsserver: make TsigSecret public ( #8434 )
...
NewServer aggregates secrets from all assigned sites and the final value
can only be reached by plugins via dnsserver.Server
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
2026-09-15 20:02:49 -07:00
Baltasar Blanco
14ed42bd1f
plugin/hosts: don't drop over-long fields silently ( #8551 )
...
#8496 fixed a silent truncation here and named the invariant in its own commit
message: entries were dropped and the hosts file simply looked shorter than it
is, with nothing in the log.
#8516 replaced that mechanism with a streaming parser bounded by maxFieldSize.
The error log #8496 added is still in parse(), but it can no longer report a
dropped entry: bufio.ErrBufferFull is consumed by the read loop, so only a real
I/O error reaches it. A field over maxFieldSize is discarded in lineParser with
no log at all, and when that field is the address the whole line goes with it.
Report both cases, once per dropped field, with the line number and the source
the entries came from.
Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com >
2026-09-15 19:24:23 -07:00
Sakıp Han Dursun
8de7a8b89d
fix(kubernetes): include structured key/value context in client-go logs ( #8490 )
2026-09-15 00:42:44 -07:00
Saleh
b0b317fdd6
plugin/dnstap: tap deferred error responses ( #8549 )
...
When the plugin chain returns an error rcode without writing a response
(it falls off the end, or returns SERVFAIL/REFUSED/FORMERR/NOTIMP), the
server generates and sends the error to the client after dnstap's ServeDNS
returns, so ResponseWriter.WriteMsg is never called and no CLIENT_RESPONSE
dnstap message is emitted. dnstap consumers then see a CLIENT_QUERY with no
matching CLIENT_RESPONSE.
Synthesize the deferred response and tap it as a CLIENT_RESPONSE, mirroring
the deferred-response handling already added to plugin/log.
Fixes #6532
Signed-off-by: Saleh <root@lr0.org >
2026-09-14 17:25:11 -07:00
Paco Cartones
22351a0d3c
fix(metrics): release listener on TLS startup failure ( #8527 )
2026-09-13 17:57:30 -07:00
Ilya Kulakov
5bd1701376
plugin/tls: document that dig supports DoT ( #8539 )
2026-09-13 17:56:16 -07:00
Ilya Kulakov
24abd331e4
fix TestReadme failed cleanup between runs ( #8545 )
...
Instance.Stop does not call shutdown callbacks. Plugins that rely
on them to release resources can leave bound listeners that affect
tests that come next.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com >
2026-09-12 07:04:41 -07:00
Baltasar Blanco
9221e099e4
docs(corefile): document that the Corefile is line oriented ( #8544 )
...
The Caddyfile parser in coredns/caddy reads the arguments of a plugin, or of one of its properties, up to the end of the line, and a closing brace on that line can be read as one of them. corefile.5.md never said so, and a one-line server block such as '. { whoami }' fails with an error that reads like a brace-matching problem.
Fixes #7267
Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com >
2026-09-11 13:02:05 -07:00
Yong Tang
19adcd8b96
Fix etcd library update issue ( #8542 )
...
This PR fixes etcd library update issue in 8492 where additional lint fix
is needed to take the latest etcd dependency.
This PR supersede 8492.
This PR closes 8492.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-10 23:59:33 -07:00
Yong Tang
6d0a0f222c
Fix DataDog library dependency issue ( #8541 )
...
This PR fixes DataDog library dependency issue where
github.com/DataDog/go-libddwaf/v5 need to be updated to allow DataDog
dependency to compile in arm.
This PR supersede 8533
This PR fixes 8533.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-10 23:19:21 -07:00
houyuwushang
0b376bda5b
test: cover Kubernetes autopath cache refresh ( #8528 )
...
Exercise Pod-dependent search paths through the native Kubernetes plugin during prefetch and stale refresh, including dual-stack resolver results.
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-10 20:55:05 -07:00
houyuwushang
8a269232e4
core/dnsserver: support explicit registration for embedded hosts ( #8525 )
...
* core/dnsserver: test host-plugin embedding with forward
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* core/dnsserver: add a directive setter for embedded hosts
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
* core/dnsserver: support explicit server registration for embedded hosts
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
---------
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-10 20:54:41 -07:00
houyuwushang
b51e6d254b
plugin/azure: allow startup with unavailable zones ( #8524 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-10 20:54:12 -07:00
dependabot[bot]
52b85e4c45
build(deps): bump google.golang.org/api from 0.293.0 to 0.297.0 ( #8535 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.293.0 to 0.297.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.293.0...v0.297.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-version: 0.297.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:53:05 -07:00
dependabot[bot]
d5a59d0ba5
build(deps): bump the k8s-io group across 1 directory with 2 updates ( #8491 )
...
Bumps the k8s-io group with 2 updates in the / directory: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery ) and [k8s.io/client-go](https://github.com/kubernetes/client-go ).
Updates `k8s.io/apimachinery` from 0.35.4 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.4...v0.37.0 )
Updates `k8s.io/client-go` from 0.35.4 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md )
- [Commits](https://github.com/kubernetes/client-go/compare/v0.35.4...v0.37.0 )
---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
dependency-version: 0.36.4
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: k8s-io
- dependency-name: k8s.io/client-go
dependency-version: 0.36.4
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: k8s-io
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:31:43 -07:00
dependabot[bot]
70615f3f90
build(deps): bump github.com/quic-go/quic-go from 0.61.0 to 0.62.0 ( #8531 )
...
Bumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go ) from 0.61.0 to 0.62.0.
- [Release notes](https://github.com/quic-go/quic-go/releases )
- [Commits](https://github.com/quic-go/quic-go/compare/v0.61.0...v0.62.0 )
---
updated-dependencies:
- dependency-name: github.com/quic-go/quic-go
dependency-version: 0.62.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:48 -07:00
dependabot[bot]
559336a33f
build(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0 ( #8534 )
...
Bumps [golang.org/x/sys](https://github.com/golang/sys ) from 0.47.0 to 0.48.0.
- [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sys
dependency-version: 0.48.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:39 -07:00
Yong Tang
4382b80a35
core: upgrade Go requirement to 1.26.0 ( #8466 )
...
* core: upgrade Go requirement to 1.26.0
As golang 1.27 has been released, this PR
- Bump Go version requirement to 1.26.0
- Update Go build version to 1.27.0
This is also for solving the issue encountered in 8092 of k8s update
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Bump golang ci
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Migrate faillint to forbidigo, as failint has not bee updated for more than a year
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-09-10 19:34:44 -07:00
dependabot[bot]
fb7e1d19fd
build(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 ( #8536 )
...
Bumps [github.com/prometheus/client_model](https://github.com/prometheus/client_model ) from 0.6.2 to 0.6.3.
- [Release notes](https://github.com/prometheus/client_model/releases )
- [Commits](https://github.com/prometheus/client_model/compare/v0.6.2...v0.6.3 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/client_model
dependency-version: 0.6.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 18:09:53 -07:00
dependabot[bot]
27540c4f3d
build(deps): bump the aws group with 6 updates ( #8530 )
...
Bumps the aws group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.43.8` | `1.45.1` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.32.39` | `1.33.2` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.19.38` | `1.20.2` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2 ) | `1.18.39` | `1.19.1` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2 ) | `1.65.10` | `1.68.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2 ) | `1.44.8` | `1.47.0` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.43.8 to 1.45.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.43.8...v1.45.1 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.39 to 1.33.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.39...config/v1.33.2 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.38 to 1.20.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.38...v1.20.2 )
Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.18.39 to 1.19.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/v1.19.1/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.39...v1.19.1 )
Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.65.10 to 1.68.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/fsx/v1.65.10...service/s3/v1.68.0 )
Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.44.8 to 1.47.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/efs/v1.44.8...service/s3/v1.47.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-version: 1.45.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.33.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-version: 1.20.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
dependency-version: 1.19.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
dependency-version: 1.68.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
dependency-version: 1.47.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:13:28 -07:00
dependabot[bot]
8431d713b7
build(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 ( #8529 )
...
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release ) from 3.0.2 to 3.0.3.
- [Release notes](https://github.com/softprops/action-gh-release/releases )
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md )
- [Commits](3d0d9888cb...efb35369e0 )
---
updated-dependencies:
- dependency-name: softprops/action-gh-release
dependency-version: 3.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:13:14 -07:00
dependabot[bot]
b96ef6ea0a
build(deps): bump github.com/prometheus/common from 0.70.1 to 0.71.0 ( #8532 )
...
Bumps [github.com/prometheus/common](https://github.com/prometheus/common ) from 0.70.1 to 0.71.0.
- [Release notes](https://github.com/prometheus/common/releases )
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prometheus/common/compare/v0.70.1...v0.71.0 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/common
dependency-version: 0.71.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:12:51 -07:00
Paco Cartones
5ac0ca4fad
fix(ready): release lock before server shutdown ( #8526 )
...
Signed-off-by: Paco Cartones <pacocartones@users.noreply.github.com >
Co-authored-by: Paco Cartones <pacocartones@users.noreply.github.com >
2026-09-08 13:15:00 -07:00
Baltasar Blanco
dea2f90f24
plugin/file: return SERVFAIL on self-referential CNAME loops ( #8475 )
...
A CNAME whose target is its own owner name is chased by externalLookup
until the depth cap, appending the same record on every pass. The reply
was NOERROR with the CNAME repeated ten times.
Self-referential DNAME already returns SERVFAIL, as do wildcard CNAME
loops. Return SERVFAIL here too. The check runs on the CNAME chase path
only, so normal responses are unaffected.
Fixes #6421
Signed-off-by: baltasarblanco <baltablanco9008@gmail.com >
2026-09-08 12:21:54 -07:00
houyuwushang
e1d3fe6bc6
plugin/forward: support DNS-over-QUIC upstreams ( #8474 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-09-07 21:51:18 -07:00
Baltasar Blanco
71a60e140b
plugin/loadbalance: validate the response before dereferencing it in WriteMsg ( #8523 )
2026-09-07 20:50:54 -07:00