mirror of
https://github.com/coredns/coredns.git
synced 2026-08-20 23:08:28 -04:00
* plugin/cache: add prefer_positive stale policy Add an opt-in serve_stale_policy that prefers an eligible success-cache answer over denial-cache entries while serve_stale is enabled. Preserve the existing ncache-first behavior when the policy is absent. Also classify SOA-backed CNAME NODATA responses in the cache so incomplete answers cannot be selected as positive stale responses. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 25da81ab-92dd-4663-b480-efd6262090c6 Signed-off-by: Nitin Nizhawan <nnizhawan@microsoft.com> * plugin/cache: retain last-known-good positive answers Keep an answering success-cache item reachable when a later NOERROR or referral response overwrites the visible cache key without answering the question. This lets prefer_positive survive empty responses, referrals, and additional-only data while leaving policy-off lookup behavior unchanged. Return the exact accepted verify refresh item instead of re-reading an ambiguous cache key, avoiding expired TTL wraparound for uncacheable replies. Add regression coverage for non-answer refreshes, NODATA, SERVFAIL, NOTIMP, stale-window expiry, and bounded verify reply shaping. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 25da81ab-92dd-4663-b480-efd6262090c6 Signed-off-by: Nitin Nizhawan <nnizhawan@microsoft.com> * plugin/cache: validate preferred stale answers Reject truncated, DNSSEC-expired, mismatched-class, unrelated ANY, and ambiguous CNAME refreshes before replacing a stale last-known-good answer. Precompute answer eligibility when cache items are created so prefer_positive hits avoid repeated CNAME walks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 25da81ab-92dd-4663-b480-efd6262090c6 Signed-off-by: Nitin Nizhawan <nnizhawan@microsoft.com> --------- Signed-off-by: Nitin Nizhawan <nnizhawan@microsoft.com> Co-authored-by: Nitin Nizhawan <nnizhawan@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 25da81ab-92dd-4663-b480-efd6262090c6
368 lines
13 KiB
Go
368 lines
13 KiB
Go
package cache
|
|
|
|
import (
|
|
"fmt"
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/coredns/caddy"
|
|
)
|
|
|
|
func TestSetup(t *testing.T) {
|
|
tests := []struct {
|
|
input string
|
|
shouldErr bool
|
|
expectedNcap int
|
|
expectedPcap int
|
|
expectedNttl time.Duration
|
|
expectedMinNttl time.Duration
|
|
expectedPttl time.Duration
|
|
expectedMinPttl time.Duration
|
|
expectedPrefetch int
|
|
}{
|
|
{`cache`, false, defaultCap, defaultCap, maxNTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache {}`, false, defaultCap, defaultCap, maxNTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache example.nl {
|
|
success 10
|
|
}`, false, defaultCap, 10, maxNTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache example.nl {
|
|
success 10 1800 30
|
|
}`, false, defaultCap, 10, maxNTTL, minNTTL, 1800 * time.Second, 30 * time.Second, 0},
|
|
{`cache example.nl {
|
|
success 10
|
|
denial 10 15
|
|
}`, false, 10, 10, 15 * time.Second, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache example.nl {
|
|
success 10
|
|
denial 10 15 2
|
|
}`, false, 10, 10, 15 * time.Second, 2 * time.Second, maxTTL, minTTL, 0},
|
|
{`cache 25 example.nl {
|
|
success 10
|
|
denial 10 15
|
|
}`, false, 10, 10, 15 * time.Second, minNTTL, 25 * time.Second, minTTL, 0},
|
|
{`cache 25 example.nl {
|
|
success 10
|
|
denial 10 15 5
|
|
}`, false, 10, 10, 15 * time.Second, 5 * time.Second, 25 * time.Second, minTTL, 0},
|
|
{`cache aaa example.nl`, false, defaultCap, defaultCap, maxNTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache {
|
|
prefetch 10
|
|
}`, false, defaultCap, defaultCap, maxNTTL, minNTTL, maxTTL, minTTL, 10},
|
|
|
|
// fails
|
|
{`cache example.nl {
|
|
success
|
|
denial 10 15
|
|
}`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache example.nl {
|
|
success 15
|
|
denial aaa
|
|
}`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache example.nl {
|
|
positive 15
|
|
negative aaa
|
|
}`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache 0 example.nl`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache -1 example.nl`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache 1 example.nl {
|
|
positive 0
|
|
}`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache 1 example.nl {
|
|
positive 0
|
|
prefetch -1
|
|
}`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache 1 example.nl {
|
|
prefetch 0 blurp
|
|
}`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
{`cache
|
|
cache`, true, defaultCap, defaultCap, maxTTL, minNTTL, maxTTL, minTTL, 0},
|
|
}
|
|
for i, test := range tests {
|
|
c := caddy.NewTestController("dns", test.input)
|
|
ca, err := cacheParse(c)
|
|
if test.shouldErr && err == nil {
|
|
t.Errorf("Test %v: Expected error but found nil", i)
|
|
continue
|
|
} else if !test.shouldErr && err != nil {
|
|
t.Errorf("Test %v: Expected no error but found error: %v", i, err)
|
|
continue
|
|
}
|
|
if test.shouldErr && err != nil {
|
|
continue
|
|
}
|
|
|
|
if ca.ncap != test.expectedNcap {
|
|
t.Errorf("Test %v: Expected ncap %v but found: %v", i, test.expectedNcap, ca.ncap)
|
|
}
|
|
if ca.pcap != test.expectedPcap {
|
|
t.Errorf("Test %v: Expected pcap %v but found: %v", i, test.expectedPcap, ca.pcap)
|
|
}
|
|
if ca.nttl != test.expectedNttl {
|
|
t.Errorf("Test %v: Expected nttl %v but found: %v", i, test.expectedNttl, ca.nttl)
|
|
}
|
|
if ca.minnttl != test.expectedMinNttl {
|
|
t.Errorf("Test %v: Expected minnttl %v but found: %v", i, test.expectedMinNttl, ca.minnttl)
|
|
}
|
|
if ca.pttl != test.expectedPttl {
|
|
t.Errorf("Test %v: Expected pttl %v but found: %v", i, test.expectedPttl, ca.pttl)
|
|
}
|
|
if ca.minpttl != test.expectedMinPttl {
|
|
t.Errorf("Test %v: Expected minpttl %v but found: %v", i, test.expectedMinPttl, ca.minpttl)
|
|
}
|
|
if ca.prefetch != test.expectedPrefetch {
|
|
t.Errorf("Test %v: Expected prefetch %v but found: %v", i, test.expectedPrefetch, ca.prefetch)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestServeStale(t *testing.T) {
|
|
tests := []struct {
|
|
input string
|
|
shouldErr bool
|
|
staleUpTo time.Duration
|
|
verifyStale bool
|
|
verifyStaleTimeout time.Duration
|
|
staleTTL time.Duration
|
|
}{
|
|
{"serve_stale", false, 1 * time.Hour, false, 0, 0},
|
|
{"serve_stale 20m", false, 20 * time.Minute, false, 0, 0},
|
|
{"serve_stale 1h20m", false, 80 * time.Minute, false, 0, 0},
|
|
{"serve_stale 0m", false, 0, false, 0, 0},
|
|
{"serve_stale 0", false, 0, false, 0, 0},
|
|
{"serve_stale 0 verify", false, 0, true, 0, 0},
|
|
{"serve_stale 0 immediate", false, 0, false, 0, 0},
|
|
{"serve_stale 0 VERIFY", false, 0, true, 0, 0},
|
|
{"serve_stale 1h immediate 30s", false, 1 * time.Hour, false, 0, 30 * time.Second},
|
|
{"serve_stale 1h immediate 30s 30s", false, 1 * time.Hour, false, 0, 30 * time.Second},
|
|
{"serve_stale 1h immediate 4294967295s", false, 1 * time.Hour, false, 0, time.Duration(^uint32(0)) * time.Second},
|
|
{"serve_stale 1h immediate 0", false, 1 * time.Hour, false, 0, 0},
|
|
{"serve_stale 1h verify 100ms", false, 1 * time.Hour, true, 100 * time.Millisecond, 0},
|
|
{"serve_stale 1h verify 100ms 30s", false, 1 * time.Hour, true, 100 * time.Millisecond, 30 * time.Second},
|
|
{"serve_stale 1h verify 100ms 30s 30s", false, 1 * time.Hour, true, 100 * time.Millisecond, 30 * time.Second},
|
|
{"serve_stale 1h verify 0", false, 1 * time.Hour, true, 0, 0},
|
|
{"serve_stale 1h verify 0 1m", false, 1 * time.Hour, true, 0, time.Minute},
|
|
{"serve_stale 1h VERIFY 250ms", false, 1 * time.Hour, true, 250 * time.Millisecond, 0},
|
|
// fails
|
|
{"serve_stale 20", true, 0, false, 0, 0},
|
|
{"serve_stale -20m", true, 0, false, 0, 0},
|
|
{"serve_stale aa", true, 0, false, 0, 0},
|
|
{"serve_stale 1m nono", true, 0, false, 0, 0},
|
|
{"serve_stale 0 after nono", true, 0, false, 0, 0},
|
|
{"serve_stale 1h immediate 100ms", true, 0, false, 0, 0},
|
|
{"serve_stale 1h immediate 4294967296s", true, 0, false, 0, 0},
|
|
{"serve_stale 1h immediate -1s", true, 0, false, 0, 0},
|
|
{"serve_stale 1h immediate garbage", true, 0, false, 0, 0},
|
|
{"serve_stale 1h immediate 30s extra", true, 0, false, 0, 0},
|
|
{"serve_stale 1h verify -1ms", true, 0, false, 0, 0},
|
|
{"serve_stale 1h verify garbage", true, 0, false, 0, 0},
|
|
{"serve_stale 1h verify 100ms 500ms", true, 0, false, 0, 0},
|
|
{"serve_stale 1h verify 100ms -1s", true, 0, false, 0, 0},
|
|
{"serve_stale 1h verify 100ms garbage", true, 0, false, 0, 0},
|
|
{"serve_stale 1h verify 100ms 30s extra", true, 0, false, 0, 0},
|
|
}
|
|
for i, test := range tests {
|
|
c := caddy.NewTestController("dns", fmt.Sprintf("cache {\n%s\n}", test.input))
|
|
ca, err := cacheParse(c)
|
|
if test.shouldErr && err == nil {
|
|
t.Errorf("Test %v: Expected error but found nil", i)
|
|
continue
|
|
} else if !test.shouldErr && err != nil {
|
|
t.Errorf("Test %v: Expected no error but found error: %v", i, err)
|
|
continue
|
|
}
|
|
if test.shouldErr && err != nil {
|
|
continue
|
|
}
|
|
if ca.staleUpTo != test.staleUpTo {
|
|
t.Errorf("Test %v: Expected stale %v but found: %v", i, test.staleUpTo, ca.staleUpTo)
|
|
}
|
|
if ca.verifyStale != test.verifyStale {
|
|
t.Errorf("Test %v: Expected verifyStale %v but found: %v", i, test.verifyStale, ca.verifyStale)
|
|
}
|
|
if ca.verifyStaleTimeout != test.verifyStaleTimeout {
|
|
t.Errorf("Test %v: Expected verifyStaleTimeout %v but found: %v", i, test.verifyStaleTimeout, ca.verifyStaleTimeout)
|
|
}
|
|
if ca.staleTTL != test.staleTTL {
|
|
t.Errorf("Test %v: Expected staleTTL %v but found: %v", i, test.staleTTL, ca.staleTTL)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestServeStaleFailureRecheck(t *testing.T) {
|
|
tests := []struct {
|
|
input string
|
|
wantRecheck time.Duration
|
|
shouldErr bool
|
|
}{
|
|
{input: "serve_stale 1h immediate 30s 30s", wantRecheck: 30 * time.Second},
|
|
{input: "serve_stale 1h immediate 0 0"},
|
|
{input: "serve_stale 1h verify 100ms 30s 250ms", wantRecheck: 250 * time.Millisecond},
|
|
{input: "serve_stale 1h verify 0 0 5m", wantRecheck: 5 * time.Minute},
|
|
{input: "serve_stale 1h immediate 30s -1s", shouldErr: true},
|
|
{input: "serve_stale 1h immediate 30s 5m1s", shouldErr: true},
|
|
{input: "serve_stale 1h immediate 30s invalid", shouldErr: true},
|
|
{input: "serve_stale 1h immediate 30s 30s extra", shouldErr: true},
|
|
{input: "serve_stale 1h verify 100ms 30s -1s", shouldErr: true},
|
|
{input: "serve_stale 1h verify 100ms 30s 30s extra", shouldErr: true},
|
|
}
|
|
|
|
for _, test := range tests {
|
|
t.Run(test.input, func(t *testing.T) {
|
|
controller := caddy.NewTestController("dns", fmt.Sprintf("cache {\n%s\n}", test.input))
|
|
ca, err := cacheParse(controller)
|
|
if test.shouldErr {
|
|
if err == nil {
|
|
t.Fatal("expected an error")
|
|
}
|
|
return
|
|
}
|
|
if err != nil {
|
|
t.Fatalf("unexpected error: %v", err)
|
|
}
|
|
if ca.staleRecheck != test.wantRecheck {
|
|
t.Fatalf("expected failure recheck %v, got %v", test.wantRecheck, ca.staleRecheck)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestServeStalePolicy(t *testing.T) {
|
|
tests := []struct {
|
|
input string
|
|
shouldErr bool
|
|
preferPositive bool
|
|
}{
|
|
{"serve_stale\nserve_stale_policy prefer_positive", false, true},
|
|
{"serve_stale_policy PREFER_POSITIVE\nserve_stale", false, true},
|
|
{"serve_stale", false, false},
|
|
// fails
|
|
{"serve_stale_policy prefer_positive", true, false},
|
|
{"serve_stale\nserve_stale_policy", true, false},
|
|
{"serve_stale\nserve_stale_policy prefer_positive extra", true, false},
|
|
{"serve_stale\nserve_stale_policy invalid", true, false},
|
|
{"serve_stale\nserve_stale_policy prefer_positive\nserve_stale_policy prefer_positive", true, false},
|
|
}
|
|
for i, test := range tests {
|
|
c := caddy.NewTestController("dns", fmt.Sprintf("cache {\n%s\n}", test.input))
|
|
ca, err := cacheParse(c)
|
|
if test.shouldErr && err == nil {
|
|
t.Errorf("Test %v: Expected error but found nil", i)
|
|
continue
|
|
} else if !test.shouldErr && err != nil {
|
|
t.Errorf("Test %v: Expected no error but found error: %v", i, err)
|
|
continue
|
|
}
|
|
if test.shouldErr {
|
|
continue
|
|
}
|
|
if ca.preferPositive != test.preferPositive {
|
|
t.Errorf("Test %v: Expected preferPositive %v but found %v", i, test.preferPositive, ca.preferPositive)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestServfail(t *testing.T) {
|
|
tests := []struct {
|
|
input string
|
|
shouldErr bool
|
|
failttl time.Duration
|
|
}{
|
|
{"servfail 1s", false, 1 * time.Second},
|
|
{"servfail 5m", false, 5 * time.Minute},
|
|
{"servfail 0s", false, 0},
|
|
{"servfail 0", false, 0},
|
|
// fails
|
|
{"servfail", true, minNTTL},
|
|
{"servfail 6m", true, minNTTL},
|
|
{"servfail 20", true, minNTTL},
|
|
{"servfail -1s", true, minNTTL},
|
|
{"servfail aa", true, minNTTL},
|
|
{"servfail 1m invalid", true, minNTTL},
|
|
}
|
|
for i, test := range tests {
|
|
c := caddy.NewTestController("dns", fmt.Sprintf("cache {\n%s\n}", test.input))
|
|
ca, err := cacheParse(c)
|
|
if test.shouldErr && err == nil {
|
|
t.Errorf("Test %v: Expected error but found nil", i)
|
|
continue
|
|
} else if !test.shouldErr && err != nil {
|
|
t.Errorf("Test %v: Expected no error but found error: %v", i, err)
|
|
continue
|
|
}
|
|
if test.shouldErr && err != nil {
|
|
continue
|
|
}
|
|
if ca.failttl != test.failttl {
|
|
t.Errorf("Test %v: Expected stale %v but found: %v", i, test.failttl, ca.staleUpTo)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestDisable(t *testing.T) {
|
|
tests := []struct {
|
|
input string
|
|
shouldErr bool
|
|
nexcept []string
|
|
pexcept []string
|
|
}{
|
|
// positive
|
|
{"disable denial example.com example.org", false, []string{"example.com.", "example.org."}, nil},
|
|
{"disable success example.com example.org", false, nil, []string{"example.com.", "example.org."}},
|
|
{"disable denial", false, []string{"."}, nil},
|
|
{"disable success", false, nil, []string{"."}},
|
|
{"disable denial example.com example.org\ndisable success example.com example.org", false,
|
|
[]string{"example.com.", "example.org."}, []string{"example.com.", "example.org."}},
|
|
// negative
|
|
{"disable invalid example.com example.org", true, nil, nil},
|
|
}
|
|
for i, test := range tests {
|
|
c := caddy.NewTestController("dns", fmt.Sprintf("cache {\n%s\n}", test.input))
|
|
ca, err := cacheParse(c)
|
|
if test.shouldErr && err == nil {
|
|
t.Errorf("Test %v: Expected error but found nil", i)
|
|
continue
|
|
} else if !test.shouldErr && err != nil {
|
|
t.Errorf("Test %v: Expected no error but found error: %v", i, err)
|
|
continue
|
|
}
|
|
if test.shouldErr {
|
|
continue
|
|
}
|
|
if fmt.Sprintf("%v", test.nexcept) != fmt.Sprintf("%v", ca.nexcept) {
|
|
t.Errorf("Test %v: Expected %v but got: %v", i, test.nexcept, ca.nexcept)
|
|
}
|
|
if fmt.Sprintf("%v", test.pexcept) != fmt.Sprintf("%v", ca.pexcept) {
|
|
t.Errorf("Test %v: Expected %v but got: %v", i, test.pexcept, ca.pexcept)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestKeepttl(t *testing.T) {
|
|
tests := []struct {
|
|
input string
|
|
shouldErr bool
|
|
}{
|
|
// positive
|
|
{"keepttl", false},
|
|
// negative
|
|
{"keepttl arg1", true},
|
|
}
|
|
for i, test := range tests {
|
|
c := caddy.NewTestController("dns", fmt.Sprintf("cache {\n%s\n}", test.input))
|
|
ca, err := cacheParse(c)
|
|
if test.shouldErr && err == nil {
|
|
t.Errorf("Test %v: Expected error but found nil", i)
|
|
continue
|
|
} else if !test.shouldErr && err != nil {
|
|
t.Errorf("Test %v: Expected no error but found error: %v", i, err)
|
|
continue
|
|
}
|
|
if test.shouldErr {
|
|
continue
|
|
}
|
|
if !ca.keepttl {
|
|
t.Errorf("Test %v: Expected keepttl enabled but disabled", i)
|
|
}
|
|
}
|
|
}
|