* core: Reject conflicting TLS policies on shared listeners.
This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
* Fix ACME
Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
* DoQ: cancel only the stalled stream, not the whole DoQ connection
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com>
* sent only RESET_STREAM, STOP_SENDING is for client cancelling stream
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com>
---------
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com>
An upstream may return a NOERROR message with an empty question section
(some plugins emit this during prefetch). response.Typify classifies it
as NoError, so key falls through to m.Question[0] and panics, taking
down the server. Skip caching such a malformed response and log a
warning instead.
Fixes#6051
Signed-off-by: Saleh <root@lr0.org>
* plugin/file: fix less to follow RFC 1034 and RFC 4034 matching and ordering requirements
- Ensure comparison is left-justified
- Ensure case folding applies only to A-Z
- Decode \DDD without allocations
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
* plugin/file: faster exit for less when a == b
Avoid two calls and two reslices.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
* plugin/file: consolidate less tests
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
* plugin/file: exit less early when there are no more labels
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
* plugin/file: match dns.PackDomainName in handling \-escapes
Compare unterminated names as root-terminating
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
* plugin/file: More tests of less.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
---------
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
NewServer aggregates secrets from all assigned sites and the final value
can only be reached by plugins via dnsserver.Server
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
#8496 fixed a silent truncation here and named the invariant in its own commit
message: entries were dropped and the hosts file simply looked shorter than it
is, with nothing in the log.
#8516 replaced that mechanism with a streaming parser bounded by maxFieldSize.
The error log #8496 added is still in parse(), but it can no longer report a
dropped entry: bufio.ErrBufferFull is consumed by the read loop, so only a real
I/O error reaches it. A field over maxFieldSize is discarded in lineParser with
no log at all, and when that field is the address the whole line goes with it.
Report both cases, once per dropped field, with the line number and the source
the entries came from.
Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com>
When the plugin chain returns an error rcode without writing a response
(it falls off the end, or returns SERVFAIL/REFUSED/FORMERR/NOTIMP), the
server generates and sends the error to the client after dnstap's ServeDNS
returns, so ResponseWriter.WriteMsg is never called and no CLIENT_RESPONSE
dnstap message is emitted. dnstap consumers then see a CLIENT_QUERY with no
matching CLIENT_RESPONSE.
Synthesize the deferred response and tap it as a CLIENT_RESPONSE, mirroring
the deferred-response handling already added to plugin/log.
Fixes#6532
Signed-off-by: Saleh <root@lr0.org>
Instance.Stop does not call shutdown callbacks. Plugins that rely
on them to release resources can leave bound listeners that affect
tests that come next.
Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
The Caddyfile parser in coredns/caddy reads the arguments of a plugin, or of one of its properties, up to the end of the line, and a closing brace on that line can be read as one of them. corefile.5.md never said so, and a one-line server block such as '. { whoami }' fails with an error that reads like a brace-matching problem.
Fixes#7267
Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com>
This PR fixes etcd library update issue in 8492 where additional lint fix
is needed to take the latest etcd dependency.
This PR supersede 8492.
This PR closes 8492.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
This PR fixes DataDog library dependency issue where
github.com/DataDog/go-libddwaf/v5 need to be updated to allow DataDog
dependency to compile in arm.
This PR supersede 8533
This PR fixes 8533.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
Exercise Pod-dependent search paths through the native Kubernetes plugin during prefetch and stale refresh, including dual-stack resolver results.
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
A CNAME whose target is its own owner name is chased by externalLookup
until the depth cap, appending the same record on every pass. The reply
was NOERROR with the CNAME repeated ten times.
Self-referential DNAME already returns SERVFAIL, as do wildcard CNAME
loops. Return SERVFAIL here too. The check runs on the CNAME chase path
only, so normal responses are unaffected.
Fixes#6421
Signed-off-by: baltasarblanco <baltablanco9008@gmail.com>
Add a max_streams option to the *https* plugin to limit the number of
concurrent HTTP/2 streams per DoH connection. This lets operators cap
per-connection concurrency (guarding against resource exhaustion) or
raise it above the Go default for high-fan-in clients that multiplex
many requests over a single connection.
Semantics match the existing *https3* plugin's max_streams:
- omitted -> Go HTTP/2 server default is used
- 0 -> use the underlying HTTP/2 transport default
- positive -> advertise exactly that many concurrent streams
- negative -> rejected at config parse time
The limit is applied via the standard library http.Server.HTTP2
(HTTP2Config.MaxConcurrentStreams) so it is advertised in the server's
SETTINGS frame.
Signed-off-by: Mekias Yohannes <mmyohannes@gmail.com>
* plugin/autopath: Fixes a nil pointer dereference panic in autopath during search path walk
When a plugin later in the chain returns a ClientWrite rcode without
writing a response (for example acl's drop action, which returns
(dns.RcodeSuccess, nil) without calling WriteMsg), autopath dereferences
a nil nw.Msg at nw.Msg.Rcode and panics. The final fallback
w.WriteMsg(firstReply) can also receive a nil firstReply for the same
reason.
Skip search path elements that produced no message, and only write the
first reply when it is non-nil. This mirrors the nil guards recently
added in plugin/minimal (#8506), plugin/dns64 (#8511) and plugin/cache
(#8512).
Signed-off-by: zjncs <18910855655@163.com>
* plugin/autopath: silence unused-parameter lint and assert no client write
Address review feedback on #8517: rename the unused 'w' parameter in
TestAutoPathNilMsgFromNext to '_w' so the revive unused-parameter check
passes, and assert that the recorder receives no message so the intended
drop/no-client-write behavior is explicit.
Signed-off-by: zjncs <18910855655@163.com>
---------
Signed-off-by: zjncs <18910855655@163.com>
* plugin/k8s_external: Fixes a nil pointer dereference panic when upstream lookup returns no response
When a CNAME-hosted service is resolved, k8s_external performs internal
upstream lookups for the target name. Upstream.Lookup can return a nil
message with a nil error when the internal self-query's plugin chain
returns a ClientWrite rcode without writing a response (for example
acl's drop action), and the a/aaaa/srv handlers then dereference
resp.Answer on a nil resp and panic.
Guard all four lookups with err == nil && resp != nil, matching the nil
checks already used in plugin/backend_lookup.go and the guard recently
added to plugin/dns64 (#8511).
Signed-off-by: zjncs <18910855655@163.com>
* plugin/k8s_external: silence unused-parameter lint in nil upstream test
The CI lint flagged the test handler's unused 'w' parameter. Rename it
to '_' so golangci-lint (revive unused-parameter) passes. No behavior
change.
Signed-off-by: zjncs <18910855655@163.com>
---------
Signed-off-by: zjncs <18910855655@163.com>
ResponseReverter.WriteMsg calls res1.Copy() without checking res1 for
nil, so any plugin further down the chain that writes a nil response
(for example a handler returning (dns.RcodeSuccess, nil) after
w.WriteMsg(nil)) panics here.
Return an error instead, mirroring the nil guard recently added to
plugin/cache's ResponseWriter.WriteMsg (#8512).
Signed-off-by: zjncs <18910855655@163.com>