Commit Graph

5135 Commits

Author SHA1 Message Date
ump45nose
b84ac4011b docs: fix anchor case in geoip plugin README (#8588)
Signed-off-by: yuwk <1729065730@qq.com>
2026-09-30 11:06:04 +01:00
Yong Tang
8f7b2a66ea plugin/cache: Fix timed stale caused refreshes (#8587) 2026-09-30 01:18:21 -07:00
Yong Tang
9fbbdd2698 plugin/tsig: reject non-final TSIG records (#8585)
This PR returns FORMERR before dispatching requests that contain a non-final TSIG.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-29 20:32:06 -07:00
Yong Tang
6ad382b53d plugin/etcd: Stop target stripping at the end of a name (#8584)
Stops stripping when the next-label operation reaches the end sentinel in DNS

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-29 20:11:44 -07:00
Yong Tang
23ba070a81 plugin/pkg/proxyproto: preserve the UDP peer for LOCAL (#8581)
This PR consumes LOCAL headers without replacing or caching the actual UDP peer address.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-29 01:19:37 -07:00
Yong Tang
d821a74af8 plugin/grpc: close clients on shutdown (#8582)
This PR closes from the plugin shutdown hook

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-29 01:19:28 -07:00
Yong Tang
594d6c9121 plugin/file: Fix race condition in file plugin closer (#8583)
This PR fixes race condition in file plugin closer

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-29 01:19:07 -07:00
llucas
0e9d7f4d05 plugin/forward ensure forward sets the DOH host (#8470)
* ensure forward sets the DOH host

Signed-off-by: ccie57654 <ccie57654@proton.me>

* added DoHHost value test

Signed-off-by: ccie57654 <ccie57654@proton.me>

---------

Signed-off-by: ccie57654 <ccie57654@proton.me>
2026-09-28 05:40:16 -07:00
jxj
72160e6e20 plugin/file: track zone mtime for reload_by_mtime (#8556)
* plugin/file: track zone mtime for reload_by_mtime

Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com>

* plugin/file: capture initial mtime before parsing

Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com>

* plugin/file: keep unloaded zones retryable after open error

Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com>

---------

Signed-off-by: git-jxj <65210887+git-jxj@users.noreply.github.com>
2026-09-28 00:22:39 -07:00
github-actions[bot]
6755e6276d auto make -f Makefile.doc (#8578)
Signed-off-by: coredns[bot] <bot@coredns.io>
Co-authored-by: coredns[bot] <bot@coredns.io>
2026-09-27 19:00:04 -07:00
Arunesh Dwivedi
f781f97334 fix: return error from zipkin NewEndpoint in trace setup (#8577) 2026-09-27 16:35:03 -07:00
Amila Senadheera
95484f76ed rewrite/cname: point to config instead of copying (#8568)
Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com>
2026-09-23 17:02:02 -07:00
dependabot[bot]
6cb01361d7 build(deps): bump google.golang.org/api from 0.297.0 to 0.298.0 (#8574)
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client) from 0.297.0 to 0.298.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.297.0...v0.298.0)

---
updated-dependencies:
- dependency-name: google.golang.org/api
  dependency-version: 0.298.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-23 17:01:00 -07:00
dependabot[bot]
73c1c17738 build(deps): bump the aws group with 6 updates (#8573)
Bumps the aws group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.46.0` | `1.47.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.33.3` | `1.33.5` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.20.3` | `1.20.5` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2) | `1.19.2` | `1.20.0` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2) | `1.69.0` | `1.70.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) | `1.48.0` | `1.50.0` |


Updates `github.com/aws/aws-sdk-go-v2` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.46.0...v1.47.0)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.3 to 1.33.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.33.3...config/v1.33.5)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.3 to 1.20.5
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.20.3...service/mq/v1.20.5)

Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.19.2 to 1.20.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/v1.20.0/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/m2/v1.19.2...v1.20.0)

Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.69.0 to 1.70.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.69.0...service/s3/v1.70.0)

Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.48.0 to 1.50.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.48.0...service/s3/v1.50.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.33.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.20.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
  dependency-version: 1.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-23 17:00:51 -07:00
dependabot[bot]
34f6827f4c build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 (#8572)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 10.0.1 to 10.1.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](20cfd1bf94...bec219d24c)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-23 17:00:38 -07:00
Ilya Kulakov
615e3d4e11 deps: bump caddy to v1.1.4 (#8562)
v1.1.4 has important fixes for parsing nested blocks.

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
2026-09-22 19:08:09 -07:00
Yong Tang
d5c1188843 plugin/rewrite: Limit rewrite cname recursion (#8570)
This PR limit rewrite cname recursion with the existing DNS server loop counter.
The issu was that rewrite cname can recurse indefinitely through internal lookups, causing crash at the end

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-22 06:23:20 -07:00
houyuwushang
5aa4dc2941 plugin/dynupdate: add durable authenticated RFC 2136 updates (#8520)
* plugin/dynupdate: add authenticated RFC 2136 updates

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: fix README test fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* test: format README fixture map

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: persist updates and bound writable zones

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: preserve middleware and fix interoperability fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* test(dynupdate): validate Kea lifecycle and bounded zone costs

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: reject duplicate directives and harden client fixtures

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/dynupdate: fix update routing and startup validation

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

---------

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-22 00:53:26 -07:00
Yong Tang
8d66643935 core: Reject conflicting TLS policies on shared listeners. (#8565)
* core: Reject conflicting TLS policies on shared listeners.

This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix ACME

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-21 23:56:27 -07:00
Amila Senadheera
559e57ec55 DoQ: cancel only the stalled stream, not the whole DoQ connection (#8567)
* DoQ: cancel only the stalled stream, not the whole DoQ connection

Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com>

* sent only RESET_STREAM, STOP_SENDING is for client cancelling stream

Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com>

---------

Signed-off-by: Amila Senadheera <amilaruk1995@gmail.com>
2026-09-21 12:49:37 -07:00
Yong Tang
5cb7cdc914 plugin/forward: Treat forward upstream hostnames as absolute FQDNs to avoid search-domain resolution. (#8563) 2026-09-19 21:37:34 -07:00
houyuwushang
ce5ee05bee plugin/forward: bound DoT connection setup for retries (#8543)
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-18 16:56:31 -07:00
Saleh
8f2d1cb7f4 plugin/cache: don't cache or panic on responses with no question (#8467)
An upstream may return a NOERROR message with an empty question section
(some plugins emit this during prefetch). response.Typify classifies it
as NoError, so key falls through to m.Question[0] and panics, taking
down the server. Skip caching such a malformed response and log a
warning instead.

Fixes #6051

Signed-off-by: Saleh <root@lr0.org>
2026-09-18 16:56:04 -07:00
dependabot[bot]
010d8a8485 build(deps): bump github.com/oschwald/geoip2-golang/v2 (#8560)
Bumps [github.com/oschwald/geoip2-golang/v2](https://github.com/oschwald/geoip2-golang) from 2.3.0 to 2.4.0.
- [Release notes](https://github.com/oschwald/geoip2-golang/releases)
- [Changelog](https://github.com/oschwald/geoip2-golang/blob/main/CHANGELOG.md)
- [Commits](https://github.com/oschwald/geoip2-golang/compare/v2.3.0...v2.4.0)

---
updated-dependencies:
- dependency-name: github.com/oschwald/geoip2-golang/v2
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 19:08:01 -07:00
Ilya Kulakov
25eb456b57 plugin/file: fix less is not up to RFC 1034 and 4034 (#8503)
* plugin/file: fix less to follow RFC 1034 and RFC 4034 matching and ordering requirements

- Ensure comparison is left-justified
- Ensure case folding applies only to A-Z
- Decode \DDD without allocations

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>

* plugin/file: faster exit for less when a == b

Avoid two calls and two reslices.

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>

* plugin/file: consolidate less tests

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>

* plugin/file: exit less early when there are no more labels

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>

* plugin/file: match dns.PackDomainName in handling \-escapes

Compare unterminated names as root-terminating

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>

* plugin/file: More tests of less.

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>

---------

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
2026-09-16 17:51:15 -07:00
houyuwushang
b93e449b2f Add opt-in JSON logging with structured DNS query fields (#8553)
* plugin/pkg/log: add opt-in JSON logging backend

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* plugin/log: emit typed query records in JSON mode

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* coremain: expose process-wide JSON logging

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

---------

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-16 17:50:39 -07:00
houyuwushang
84a93a0b89 plugin/file: reject SOA owners that do not match the zone (#8555)
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-16 17:49:58 -07:00
dependabot[bot]
73198897ef build(deps): bump golang.org/x/net from 0.58.0 to 0.59.0 (#8559)
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.58.0 to 0.59.0.
- [Commits](https://github.com/golang/net/compare/v0.58.0...v0.59.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:49:02 -07:00
dependabot[bot]
78837fa799 build(deps): bump the codeql group with 4 updates (#8557)
Bumps the codeql group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/autobuild](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](cdf488f595...b96794f015)

Updates `github/codeql-action/autobuild` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](cdf488f595...b96794f015)

Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](cdf488f595...b96794f015)

Updates `github/codeql-action/upload-sarif` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](cdf488f595...b96794f015)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql
- dependency-name: github/codeql-action/autobuild
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:51 -07:00
dependabot[bot]
c22146e348 build(deps): bump the aws group with 6 updates (#8558)
Bumps the aws group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.45.1` | `1.46.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.33.2` | `1.33.3` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2) | `1.20.2` | `1.20.3` |
| [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2) | `1.19.1` | `1.19.2` |
| [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2) | `1.68.0` | `1.69.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) | `1.47.0` | `1.48.0` |


Updates `github.com/aws/aws-sdk-go-v2` from 1.45.1 to 1.46.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.45.1...v1.46.0)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.33.2 to 1.33.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.33.2...config/v1.33.3)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.20.2 to 1.20.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.20.2...v1.20.3)

Updates `github.com/aws/aws-sdk-go-v2/feature/ec2/imds` from 1.19.1 to 1.19.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.19.1...service/m2/v1.19.2)

Updates `github.com/aws/aws-sdk-go-v2/service/route53` from 1.68.0 to 1.69.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.68.0...service/s3/v1.69.0)

Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.47.0...service/s3/v1.48.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.33.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.20.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
  dependency-version: 1.19.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
  dependency-version: 1.69.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:39 -07:00
dependabot[bot]
991401324e build(deps): bump golang.org/x/crypto from 0.55.0 to 0.57.0 (#8561)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.55.0 to 0.57.0.
- [Commits](https://github.com/golang/crypto/compare/v0.55.0...v0.57.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:48:19 -07:00
Ilya Kulakov
1e550ac71a core/dnsserver: make TsigSecret public (#8434)
NewServer aggregates secrets from all assigned sites and the final value
can only be reached by plugins via dnsserver.Server

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
2026-09-15 20:02:49 -07:00
Baltasar Blanco
14ed42bd1f plugin/hosts: don't drop over-long fields silently (#8551)
#8496 fixed a silent truncation here and named the invariant in its own commit
message: entries were dropped and the hosts file simply looked shorter than it
is, with nothing in the log.

#8516 replaced that mechanism with a streaming parser bounded by maxFieldSize.
The error log #8496 added is still in parse(), but it can no longer report a
dropped entry: bufio.ErrBufferFull is consumed by the read loop, so only a real
I/O error reaches it. A field over maxFieldSize is discarded in lineParser with
no log at all, and when that field is the address the whole line goes with it.

Report both cases, once per dropped field, with the line number and the source
the entries came from.

Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com>
2026-09-15 19:24:23 -07:00
Sakıp Han Dursun
8de7a8b89d fix(kubernetes): include structured key/value context in client-go logs (#8490) 2026-09-15 00:42:44 -07:00
Saleh
b0b317fdd6 plugin/dnstap: tap deferred error responses (#8549)
When the plugin chain returns an error rcode without writing a response
(it falls off the end, or returns SERVFAIL/REFUSED/FORMERR/NOTIMP), the
server generates and sends the error to the client after dnstap's ServeDNS
returns, so ResponseWriter.WriteMsg is never called and no CLIENT_RESPONSE
dnstap message is emitted. dnstap consumers then see a CLIENT_QUERY with no
matching CLIENT_RESPONSE.

Synthesize the deferred response and tap it as a CLIENT_RESPONSE, mirroring
the deferred-response handling already added to plugin/log.

Fixes #6532

Signed-off-by: Saleh <root@lr0.org>
2026-09-14 17:25:11 -07:00
Paco Cartones
22351a0d3c fix(metrics): release listener on TLS startup failure (#8527) 2026-09-13 17:57:30 -07:00
Ilya Kulakov
5bd1701376 plugin/tls: document that dig supports DoT (#8539) 2026-09-13 17:56:16 -07:00
Ilya Kulakov
24abd331e4 fix TestReadme failed cleanup between runs (#8545)
Instance.Stop does not call shutdown callbacks. Plugins that rely
on them to release resources can leave bound listeners that affect
tests that come next.

Signed-off-by: Ilya Kulakov <kulakov.ilya@gmail.com>
2026-09-12 07:04:41 -07:00
Baltasar Blanco
9221e099e4 docs(corefile): document that the Corefile is line oriented (#8544)
The Caddyfile parser in coredns/caddy reads the arguments of a plugin, or of one of its properties, up to the end of the line, and a closing brace on that line can be read as one of them. corefile.5.md never said so, and a one-line server block such as '. { whoami }' fails with an error that reads like a brace-matching problem.

Fixes #7267

Signed-off-by: Baltasar Blanco <baltasarblanco.dev@gmail.com>
2026-09-11 13:02:05 -07:00
Yong Tang
19adcd8b96 Fix etcd library update issue (#8542)
This PR fixes etcd library update issue in 8492 where additional lint fix
is needed to take the latest etcd dependency.

This PR supersede 8492.

This PR closes 8492.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-10 23:59:33 -07:00
Yong Tang
6d0a0f222c Fix DataDog library dependency issue (#8541)
This PR fixes DataDog library dependency issue where
github.com/DataDog/go-libddwaf/v5 need to be updated to allow DataDog
dependency to compile in arm.

This PR supersede 8533

This PR fixes 8533.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-10 23:19:21 -07:00
houyuwushang
0b376bda5b test: cover Kubernetes autopath cache refresh (#8528)
Exercise Pod-dependent search paths through the native Kubernetes plugin during prefetch and stale refresh, including dual-stack resolver results.

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-10 20:55:05 -07:00
houyuwushang
8a269232e4 core/dnsserver: support explicit registration for embedded hosts (#8525)
* core/dnsserver: test host-plugin embedding with forward

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* core/dnsserver: add a directive setter for embedded hosts

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

* core/dnsserver: support explicit server registration for embedded hosts

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>

---------

Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-10 20:54:41 -07:00
houyuwushang
b51e6d254b plugin/azure: allow startup with unavailable zones (#8524)
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com>
2026-09-10 20:54:12 -07:00
dependabot[bot]
52b85e4c45 build(deps): bump google.golang.org/api from 0.293.0 to 0.297.0 (#8535)
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client) from 0.293.0 to 0.297.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.293.0...v0.297.0)

---
updated-dependencies:
- dependency-name: google.golang.org/api
  dependency-version: 0.297.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:53:05 -07:00
dependabot[bot]
d5a59d0ba5 build(deps): bump the k8s-io group across 1 directory with 2 updates (#8491)
Bumps the k8s-io group with 2 updates in the / directory: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) and [k8s.io/client-go](https://github.com/kubernetes/client-go).


Updates `k8s.io/apimachinery` from 0.35.4 to 0.37.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.4...v0.37.0)

Updates `k8s.io/client-go` from 0.35.4 to 0.37.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.35.4...v0.37.0)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-io
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-io
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:31:43 -07:00
dependabot[bot]
70615f3f90 build(deps): bump github.com/quic-go/quic-go from 0.61.0 to 0.62.0 (#8531)
Bumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 0.61.0 to 0.62.0.
- [Release notes](https://github.com/quic-go/quic-go/releases)
- [Commits](https://github.com/quic-go/quic-go/compare/v0.61.0...v0.62.0)

---
updated-dependencies:
- dependency-name: github.com/quic-go/quic-go
  dependency-version: 0.62.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:48 -07:00
dependabot[bot]
559336a33f build(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0 (#8534)
Bumps [golang.org/x/sys](https://github.com/golang/sys) from 0.47.0 to 0.48.0.
- [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-10 20:08:39 -07:00
Yong Tang
4382b80a35 core: upgrade Go requirement to 1.26.0 (#8466)
* core: upgrade Go requirement to 1.26.0

As golang 1.27 has been released, this PR
- Bump Go version requirement to 1.26.0
- Update Go build version to 1.27.0

This is also for solving the issue encountered in 8092 of k8s update

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Bump golang ci

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Migrate faillint to forbidigo, as failint has not bee updated for more than a year

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
2026-09-10 19:34:44 -07:00
dependabot[bot]
fb7e1d19fd build(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#8536)
Bumps [github.com/prometheus/client_model](https://github.com/prometheus/client_model) from 0.6.2 to 0.6.3.
- [Release notes](https://github.com/prometheus/client_model/releases)
- [Commits](https://github.com/prometheus/client_model/compare/v0.6.2...v0.6.3)

---
updated-dependencies:
- dependency-name: github.com/prometheus/client_model
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 18:09:53 -07:00