Commit Graph

5091 Commits

Author SHA1 Message Date
dependabot[bot]
52b85e4c45 build(deps): bump google.golang.org/api from 0.293.0 to 0.297.0 (#8535)
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client) from 0.293.0 to 0.297.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.293.0...v0.297.0)

---
updated-dependencies:
- dependency-name: google.golang.org/api
  dependency-version: 0.297.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:53:05 -07:00
dependabot[bot]
d5a59d0ba5 build(deps): bump the k8s-io group across 1 directory with 2 updates (#8491)
Bumps the k8s-io group with 2 updates in the / directory: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) and [k8s.io/client-go](https://github.com/kubernetes/client-go).


Updates `k8s.io/apimachinery` from 0.35.4 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.4...v0.37.0)

Updates `k8s.io/client-go` from 0.35.4 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.35.4...v0.37.0)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-io
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-io
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:31:43 -07:00
dependabot[bot]
70615f3f90 build(deps): bump github.com/quic-go/quic-go from 0.61.0 to 0.62.0 (#8531)
Bumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 0.61.0 to 0.62.0.
- [Release notes](https://github.com/quic-go/quic-go/releases)
- [Commits](https://github.com/quic-go/quic-go/compare/v0.61.0...v0.62.0)

---
updated-dependencies:
- dependency-name: github.com/quic-go/quic-go
  dependency-version: 0.62.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:48 -07:00
dependabot[bot]
559336a33f build(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0 (#8534)
Bumps [golang.org/x/sys](https://github.com/golang/sys) from 0.47.0 to 0.48.0.
- [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:39 -07:00
Yong Tang
4382b80a35 core: upgrade Go requirement to 1.26.0 (#8466)
* core: upgrade Go requirement to 1.26.0

As golang 1.27 has been released, this PR
- Bump Go version requirement to 1.26.0
- Update Go build version to 1.27.0

This is also for solving the issue encountered in 8092 of k8s update

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Bump golang ci

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Migrate faillint to forbidigo, as failint has not bee updated for more than a year

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-10 19:34:44 -07:00
dependabot[bot]
fb7e1d19fd build(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#8536)
Bumps [github.com/prometheus/client_model](https://github.com/prometheus/client_model) from 0.6.2 to 0.6.3.
- [Release notes](https://github.com/prometheus/client_model/releases)
- [Commits](https://github.com/prometheus/client_model/compare/v0.6.2...v0.6.3)

---
updated-dependencies:
- dependency-name: github.com/prometheus/client_model
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 18:09:53 -07:00
dependabot[bot]
27540c4f3d build(deps): bump the aws group with 6 updates (#8530)
Bumps the aws group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.43.8` | `1.45.1` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.39` | `1.33.2` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.19.38` | `1.20.2` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2) | `1.18.39` | `1.19.1` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2) | `1.65.10` | `1.68.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) | `1.44.8` | `1.47.0` |


Updates `github.com/aws/aws-sdk-go-v2` from 1.43.8 to 1.45.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.43.8...v1.45.1)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.39 to 1.33.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.39...config/v1.33.2)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.38 to 1.20.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.38...v1.20.2)

Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.18.39 to 1.19.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/v1.19.1/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.39...v1.19.1)

Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.65.10 to 1.68.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/fsx/v1.65.10...service/s3/v1.68.0)

Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.44.8 to 1.47.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/efs/v1.44.8...service/s3/v1.47.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.45.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.33.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
  dependency-version: 1.68.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:13:28 -07:00
dependabot[bot]
8431d713b7 build(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 (#8529)
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 3.0.2 to 3.0.3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](3d0d9888cb...efb35369e0)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:13:14 -07:00
dependabot[bot]
b96ef6ea0a build(deps): bump github.com/prometheus/common from 0.70.1 to 0.71.0 (#8532)
Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.70.1 to 0.71.0.
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](https://github.com/prometheus/common/compare/v0.70.1...v0.71.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/common
  dependency-version: 0.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 08:12:51 -07:00
Paco Cartones
5ac0ca4fad fix(ready): release lock before server shutdown (#8526)
Signed-off-by: Paco Cartones <pacocartones@users.noreply.github.com>
Co-authored-by: Paco Cartones <pacocartones@users.noreply.github.com>
2026-09-08 13:15:00 -07:00
Baltasar Blanco
dea2f90f24 plugin/file: return SERVFAIL on self-referential CNAME loops (#8475)
A CNAME whose target is its own owner name is chased by externalLookup
until the depth cap, appending the same record on every pass. The reply
was NOERROR with the CNAME repeated ten times.

Self-referential DNAME already returns SERVFAIL, as do wildcard CNAME
loops. Return SERVFAIL here too. The check runs on the CNAME chase path
only, so normal responses are unaffected.

Fixes #6421

Signed-off-by: baltasarblanco <baltablanco9008@gmail.com>
2026-09-08 12:21:54 -07:00
houyuwushang
e1d3fe6bc6 plugin/forward: support DNS-over-QUIC upstreams (#8474)
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-07 21:51:18 -07:00
Baltasar Blanco
71a60e140b plugin/loadbalance: validate the response before dereferencing it in WriteMsg (#8523) 2026-09-07 20:50:54 -07:00
sam lockart
9fb1859b23 fix(reload): broadcast shutdown signal (#8504)
* fix(reload): broadcast shutdown signal

Signed-off-by: alam0rt <sam@samlockart.com>

* fix(reload): scope shutdown state to instances

Signed-off-by: alam0rt <sam@samlockart.com>

---------

Signed-off-by: alam0rt <sam@samlockart.com>
2026-09-06 19:40:07 -07:00
Yash Singh
b24a8b7ddd Bump golang to 1.26.7 (#8472)
Signed-off-by: yashsingh74 <yashsingh1774@gmail.com>
2026-09-06 19:21:02 -07:00
myohannes
2b8c305203 plugin/https: Add max_streams to limit HTTP/2 concurrent streams (#8522)
Add a max_streams option to the *https* plugin to limit the number of
concurrent HTTP/2 streams per DoH connection. This lets operators cap
per-connection concurrency (guarding against resource exhaustion) or
raise it above the Go default for high-fan-in clients that multiplex
many requests over a single connection.

Semantics match the existing *https3* plugin's max_streams:
- omitted  -> Go HTTP/2 server default is used
- 0        -> use the underlying HTTP/2 transport default
- positive -> advertise exactly that many concurrent streams
- negative -> rejected at config parse time

The limit is applied via the standard library http.Server.HTTP2
(HTTP2Config.MaxConcurrentStreams) so it is advertised in the server's
SETTINGS frame.

Signed-off-by: Mekias Yohannes <mmyohannes@gmail.com>
2026-09-06 19:16:44 -07:00
Paco Cartones
558c9757a9 plugin/hosts: parse hosts files with bufio.Reader (#8516) 2026-09-05 17:39:42 -07:00
Zhao Jianing
b564fcd869 plugin/autopath: Fixes a nil pointer dereference panic in autopath during search path walk (#8517)
* plugin/autopath: Fixes a nil pointer dereference panic in autopath during search path walk

When a plugin later in the chain returns a ClientWrite rcode without
writing a response (for example acl's drop action, which returns
(dns.RcodeSuccess, nil) without calling WriteMsg), autopath dereferences
a nil nw.Msg at nw.Msg.Rcode and panics. The final fallback
w.WriteMsg(firstReply) can also receive a nil firstReply for the same
reason.

Skip search path elements that produced no message, and only write the
first reply when it is non-nil. This mirrors the nil guards recently
added in plugin/minimal (#8506), plugin/dns64 (#8511) and plugin/cache
(#8512).

Signed-off-by: zjncs <18910855655@163.com>

* plugin/autopath: silence unused-parameter lint and assert no client write

Address review feedback on #8517: rename the unused 'w' parameter in
TestAutoPathNilMsgFromNext to '_w' so the revive unused-parameter check
passes, and assert that the recorder receives no message so the intended
drop/no-client-write behavior is explicit.

Signed-off-by: zjncs <18910855655@163.com>

---------

Signed-off-by: zjncs <18910855655@163.com>
2026-09-05 02:20:27 -07:00
houyuwushang
b6987aeb4a request: stop echoing unhandled EDNS options (#8514)
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-04 18:14:53 -07:00
houyuwushang
895eab37e8 plugin/kubernetes: isolate NS address test fixtures (#8513)
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-04 18:14:27 -07:00
Zhao Jianing
99b203f6bb plugin/k8s_external: Fixes a nil pointer dereference panic when upstream lookup returns no response (#8518)
* plugin/k8s_external: Fixes a nil pointer dereference panic when upstream lookup returns no response

When a CNAME-hosted service is resolved, k8s_external performs internal
upstream lookups for the target name. Upstream.Lookup can return a nil
message with a nil error when the internal self-query's plugin chain
returns a ClientWrite rcode without writing a response (for example
acl's drop action), and the a/aaaa/srv handlers then dereference
resp.Answer on a nil resp and panic.

Guard all four lookups with err == nil && resp != nil, matching the nil
checks already used in plugin/backend_lookup.go and the guard recently
added to plugin/dns64 (#8511).

Signed-off-by: zjncs <18910855655@163.com>

* plugin/k8s_external: silence unused-parameter lint in nil upstream test

The CI lint flagged the test handler's unused 'w' parameter. Rename it
to '_' so golangci-lint (revive unused-parameter) passes. No behavior
change.

Signed-off-by: zjncs <18910855655@163.com>

---------

Signed-off-by: zjncs <18910855655@163.com>
2026-09-04 18:03:47 -07:00
Zhao Jianing
fe9dffcd13 plugin/rewrite: Fixes a nil pointer dereference panic in ResponseReverter.WriteMsg (#8519)
ResponseReverter.WriteMsg calls res1.Copy() without checking res1 for
nil, so any plugin further down the chain that writes a nil response
(for example a handler returning (dns.RcodeSuccess, nil) after
w.WriteMsg(nil)) panics here.

Return an error instead, mirroring the nil guard recently added to
plugin/cache's ResponseWriter.WriteMsg (#8512).

Signed-off-by: zjncs <18910855655@163.com>
2026-09-04 18:02:52 -07:00
Yong Tang
c2e309e2e4 plugin/cache: Prevents a nil pointer dereference panic in the cache prefetch (#8512)
* plugin/cache: Prevents a nil pointer dereference panic in the cache prefetch

This PR prevents a nil pointer dereference panic in the cache prefetch, by
adding nil guards

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Address comment

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-03 01:11:33 -07:00
Ilya Kulakov
c942ca7c36 plugin: use Zones.Contains when any match suffices (#8505) 2026-09-02 23:59:58 -07:00
Yong Tang
f1d835aa51 plugin/dns64: Fixes a nil pointer dereference panic in dns64 during response (#8511)
This PR fixes a nil pointer dereference panic in dns64 during response,
when the internal A-record upstream re-lookup returns a nil response.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-02 21:07:28 -07:00
Yong Tang
88ab058ba2 plugin/minimal: Fixes a nil pointer dereference panic in minimal prefetch response processing (#8506)
* plugin/minimal: Fixes a nil pointer dereference panic in minimal prefetch response processing

This PR fixes a nil pointer dereference panic in minimal prefetch response processing

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix lint

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-02 07:58:49 -07:00
dependabot[bot]
a87f9efcc5 build(deps): bump github.com/prometheus/exporter-toolkit (#8510)
Bumps [github.com/prometheus/exporter-toolkit](https://github.com/prometheus/exporter-toolkit) from 0.18.0 to 0.19.0.
- [Release notes](https://github.com/prometheus/exporter-toolkit/releases)
- [Commits](https://github.com/prometheus/exporter-toolkit/compare/v0.18.0...v0.19.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/exporter-toolkit
  dependency-version: 0.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 07:04:25 -07:00
dependabot[bot]
b8060a1e80 build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#8509)
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.83.1 to 1.83.2.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.83.1...v1.83.2)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 07:04:09 -07:00
dependabot[bot]
947bc75578 build(deps): bump the aws group with 6 updates (#8508)
Bumps the aws group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.43.7` | `1.43.8` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.38` | `1.32.39` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.19.37` | `1.19.38` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2) | `1.18.38` | `1.18.39` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2) | `1.65.9` | `1.65.10` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) | `1.44.7` | `1.44.8` |


Updates `github.com/aws/aws-sdk-go-v2` from 1.43.7 to 1.43.8
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.43.7...v1.43.8)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.38 to 1.32.39
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.38...config/v1.32.39)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.37 to 1.19.38
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.37...credentials/v1.19.38)

Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.18.38 to 1.18.39
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.38...config/v1.18.39)

Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.65.9 to 1.65.10
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/fsx/v1.65.9...service/fsx/v1.65.10)

Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.44.7 to 1.44.8
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ssm/v1.44.7...service/efs/v1.44.8)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.43.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.39
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.19.38
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
  dependency-version: 1.18.39
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
  dependency-version: 1.65.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.44.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 07:03:45 -07:00
dependabot[bot]
190dc81805 build(deps): bump the codeql group with 4 updates (#8507)
Bumps the codeql group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.8 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](db488ddef3...cdf488f595)

Updates `github/codeql-action/autobuild` from 4.37.8 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](db488ddef3...cdf488f595)

Updates `github/codeql-action/analyze` from 4.37.8 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](db488ddef3...cdf488f595)

Updates `github/codeql-action/upload-sarif` from 4.37.8 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](db488ddef3...cdf488f595)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
- dependency-name: github/codeql-action/autobuild
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 07:03:32 -07:00
github-actions[bot]
2ad79f66fa auto make -f Makefile.doc (#8500) 2026-09-01 02:41:41 -07:00
Paco Cartones
85aa27cd9c plugin/hosts: don't drop entries after an over-long line (#8496)
bufio.Scanner stops at the first line longer than its 64KiB default
buffer and reports bufio.ErrTooLong from Err(). parse() never checked
Err(), so that line and every entry after it were dropped silently: the
hosts file simply looked shorter than it is, with nothing in the log.

Raise the scanner's limit to 1MiB (the scanner still grows its buffer
lazily, so nothing is preallocated up front) and log an error if the
scan does stop early, so the truncation is at least visible.

Signed-off-by: Paco Cartones <pacocartones@users.noreply.github.com>
Co-authored-by: Paco Cartones <pacocartones@users.noreply.github.com>
2026-09-01 00:01:04 -07:00
Ilya Kulakov
ac796cd723 test: fix flaky tests that don't check dns.Exchange response is non-nil (#8501)
dns.Exchange may return nil on error.

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
2026-08-31 22:55:17 -07:00
dependabot[bot]
c113fe4876 build(deps): bump the codeql group with 4 updates (#8493) 2026-08-29 02:59:23 -07:00
dependabot[bot]
db30320f75 build(deps): bump github.com/prometheus/exporter-toolkit (#8495) 2026-08-29 02:59:11 -07:00
dependabot[bot]
7b33507933 build(deps): bump the aws group with 6 updates (#8494) 2026-08-29 02:59:00 -07:00
Yong Tang
8a7312eb57 Group AWS SDK v2 modules so related updates land together in one PR. (#8489)
* Group AWS SDK v2 modules so related updates land together in one PR.

This PR Group AWS SDK v2 modules so related updates land together in one PR.
Also rename the k8s/etcd group keys to valid Dependabot identifiers.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Update

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-08-27 19:06:55 -07:00
dependabot[bot]
78c7c61d3c build(deps): bump github.com/aws/aws-sdk-go-v2/config (#8483)
Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) from 1.32.36 to 1.32.37.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.36...config/v1.32.37)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.37
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-27 01:35:26 -07:00
dependabot[bot]
31643259cf build(deps): bump github.com/aws/aws-sdk-go-v2/credentials (#8486) 2026-08-26 23:36:01 -07:00
dependabot[bot]
4e2ac5e250 build(deps): bump golang.org/x/net from 0.57.0 to 0.58.0 (#8485) 2026-08-26 23:35:47 -07:00
dependabot[bot]
dcd09b70fb build(deps): bump github.com/aws/aws-sdk-go-v2/service/route53 (#8479) 2026-08-26 21:08:28 -07:00
dependabot[bot]
a15fc63b41 build(deps): bump github.com/aws/aws-sdk-go-v2/feature/ec2/imds (#8477)
Bumps [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2) from 1.18.36 to 1.18.37.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.36...config/v1.18.37)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
  dependency-version: 1.18.37
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-26 15:34:28 -07:00
houyuwushang
789b8d1665 plugin/tsig: expose validated TSIG key identity (#8471)
Store the normalized key name in the request context only after successful TSIG verification. This lets downstream plugins distinguish unsigned requests from authenticated requests and authorize by key without relying on the stripped TSIG RR or exposing secret material.

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-08-26 14:13:48 -07:00
dependabot[bot]
ff06b2a593 build(deps): bump github.com/aws/aws-sdk-go-v2/service/secretsmanager (#8487)
Bumps [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) from 1.44.5 to 1.44.6.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/mgn/v1.44.5...service/ssm/v1.44.6)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.44.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-26 14:12:42 -07:00
dependabot[bot]
131bc60e0d build(deps): bump the codeql group with 4 updates (#8481)
Bumps the codeql group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](5595ccaf91...ff2f1c621b)

Updates `github/codeql-action/autobuild` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](5595ccaf91...ff2f1c621b)

Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](5595ccaf91...ff2f1c621b)

Updates `github/codeql-action/upload-sarif` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](5595ccaf91...ff2f1c621b)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
- dependency-name: github/codeql-action/autobuild
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-26 14:12:15 -07:00
dependabot[bot]
fe0d044bc0 build(deps): bump github.com/miekg/dns from 1.1.72 to 1.1.73 (#8480)
Bumps [github.com/miekg/dns](https://github.com/miekg/dns) from 1.1.72 to 1.1.73.
- [Commits](https://github.com/miekg/dns/compare/v1.1.72...v1.1.73)

---
updated-dependencies:
- dependency-name: github.com/miekg/dns
  dependency-version: 1.1.73
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-26 14:11:58 -07:00
dependabot[bot]
a21b29694d build(deps): bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (#8482)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 10.0.0 to 10.0.1.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](ae62891fec...20cfd1bf94)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-26 14:11:46 -07:00
dependabot[bot]
5526852c39 build(deps): bump google.golang.org/grpc from 1.83.0 to 1.83.1 (#8484)
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.83.0 to 1.83.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.83.0...v1.83.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-26 14:11:34 -07:00
dependabot[bot]
9bb02c3d77 build(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#8488)
Bumps [github.com/stretchr/testify](https://github.com/stretchr/testify) from 1.12.0 to 1.12.1.
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](https://github.com/stretchr/testify/compare/v1.12.0...v1.12.1)

---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-26 14:11:22 -07:00
houyuwushang
70b5d6b5be core/dnsserver: add opt-in opcode admission (#8469)
Keep miekg/dns's default request policy unless a plugin explicitly registers an additional opcode. Aggregate the policy at the listener, then enforce it again after zone routing so mixed server blocks on one socket remain isolated.

Apply the same policy to UDP, TCP, and DNS-over-TLS while preserving TSIG verification and the one-question requirement.

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-08-26 01:41:28 -07:00