diff options
author | 2016-04-14 07:33:03 +0100 | |
---|---|---|
committer | 2016-04-14 07:33:03 +0100 | |
commit | eb1f21bfff2d32858af632450a18d7f661ee0c3a (patch) | |
tree | 8840c6d54e5de707214479accff949de5fc62711 /middleware/file/secondary.go | |
parent | ec343ce0ce994c95b9a9efbcf21f59d3784f17df (diff) | |
download | coredns-eb1f21bfff2d32858af632450a18d7f661ee0c3a.tar.gz coredns-eb1f21bfff2d32858af632450a18d7f661ee0c3a.tar.zst coredns-eb1f21bfff2d32858af632450a18d7f661ee0c3a.zip |
Drop NSEC3 zone (#120)
Error out when parsing and transferring such a zone. If we would serve
it we would give out the wrong answers, leading to (probably) validation
failures...
Fixes #114
Diffstat (limited to 'middleware/file/secondary.go')
-rw-r--r-- | middleware/file/secondary.go | 21 |
1 files changed, 14 insertions, 7 deletions
diff --git a/middleware/file/secondary.go b/middleware/file/secondary.go index 66b1daa98..9b3886a36 100644 --- a/middleware/file/secondary.go +++ b/middleware/file/secondary.go @@ -1,6 +1,7 @@ package file import ( + "fmt" "log" "time" @@ -28,27 +29,33 @@ Transfer: t := new(dns.Transfer) c, err := t.In(m, tr) if err != nil { - log.Printf("[ERROR] Failed to setup transfer %s with %s: %v", z.name, tr, err) + log.Printf("[ERROR] Failed to setup transfer `%s' with `%s': %v", z.name, tr, err) Err = err continue Transfer } for env := range c { if env.Error != nil { - log.Printf("[ERROR] Failed to parse transfer %s: %v", z.name, env.Error) + log.Printf("[ERROR] Failed to parse transfer `%s': %v", z.name, env.Error) Err = env.Error continue Transfer } for _, rr := range env.RR { - if rr.Header().Rrtype == dns.TypeSOA { + switch h := rr.Header().Rrtype; h { + case dns.TypeSOA: z1.SOA = rr.(*dns.SOA) - continue - } - if rr.Header().Rrtype == dns.TypeRRSIG { + case dns.TypeNSEC3, dns.TypeNSEC3PARAM: + err := fmt.Errorf("NSEC3 zone is not supported, dropping") + log.Printf("[ERROR] Failed to parse transfer `%s': %v", z.name, err) + return err + case dns.TypeRRSIG: if x, ok := rr.(*dns.RRSIG); ok && x.TypeCovered == dns.TypeSOA { z1.SIG = append(z1.SIG, x) + continue } + fallthrough + default: + z1.Insert(rr) } - z1.Insert(rr) } } Err = nil |