aboutsummaryrefslogtreecommitdiff
path: root/request
diff options
context:
space:
mode:
authorGravatar Miek Gieben <miek@miek.nl> 2018-12-06 21:18:11 +0000
committerGravatar GitHub <noreply@github.com> 2018-12-06 21:18:11 +0000
commitfc667b98e0587dcebe19183b83f99059513dba0e (patch)
treefe45c8a3659458427d2114c4767308b362a807af /request
parentf51c110511c13b80c7d7234c3d56dbefa79705a2 (diff)
downloadcoredns-fc667b98e0587dcebe19183b83f99059513dba0e.tar.gz
coredns-fc667b98e0587dcebe19183b83f99059513dba0e.tar.zst
coredns-fc667b98e0587dcebe19183b83f99059513dba0e.zip
Fix EDNS0 compliance (#2357)
* Fix EDNS0 compliance Do SizeAndDo in the server (ScrubWriter) and remove all uses of this from the plugins. Also *always* do it. This is to get into compliance for https://dnsflagday.net/. The pkg/edns0 now exports the EDNS0 options we understand; this is exported to allow plugins add things there. The *rewrite* plugin used this to add custom EDNS0 option codes that the server needs to understand. This also needs a new release of miekg/dns because it triggered a race-condition that was basicly there forever. See: * https://github.com/miekg/dns/issues/857 * https://github.com/miekg/dns/pull/859 Running a test instance and pointing the https://ednscomp.isc.org/ednscomp to it shows the tests are now fixed: ~~~ EDNS Compliance Tester Checking: 'miek.nl' as at 2018-12-01T17:53:15Z miek.nl. @147.75.204.203 (drone.coredns.io.): dns=ok edns=ok edns1=ok edns@512=ok ednsopt=ok edns1opt=ok do=ok ednsflags=ok docookie=ok edns512tcp=ok optlist=ok miek.nl. @2604:1380:2002:a000::1 (drone.coredns.io.): dns=ok edns=ok edns1=ok edns@512=ok ednsopt=ok edns1opt=ok do=ok ednsflags=ok docookie=ok edns512tcp=ok optlist=ok All Ok Codes ok - test passed. ~~~ Signed-off-by: Miek Gieben <miek@miek.nl> Signed-off-by: Miek Gieben <miek@miek.nl> * typos in comments Signed-off-by: Miek Gieben <miek@miek.nl>
Diffstat (limited to 'request')
-rw-r--r--request/edns0.go31
-rw-r--r--request/request.go12
-rw-r--r--request/request_test.go8
-rw-r--r--request/writer.go2
4 files changed, 42 insertions, 11 deletions
diff --git a/request/edns0.go b/request/edns0.go
new file mode 100644
index 000000000..89eb6b468
--- /dev/null
+++ b/request/edns0.go
@@ -0,0 +1,31 @@
+package request
+
+import (
+ "github.com/coredns/coredns/plugin/pkg/edns"
+
+ "github.com/miekg/dns"
+)
+
+func supportedOptions(o []dns.EDNS0) []dns.EDNS0 {
+ var supported = make([]dns.EDNS0, 0, 3)
+ // For as long as possible try avoid looking up in the map, because that need an Rlock.
+ for _, opt := range o {
+ switch code := opt.Option(); code {
+ case dns.EDNS0NSID:
+ fallthrough
+ case dns.EDNS0EXPIRE:
+ fallthrough
+ case dns.EDNS0COOKIE:
+ fallthrough
+ case dns.EDNS0TCPKEEPALIVE:
+ fallthrough
+ case dns.EDNS0PADDING:
+ supported = append(supported, opt)
+ default:
+ if edns.SupportedOption(code) {
+ supported = append(supported, opt)
+ }
+ }
+ }
+ return supported
+}
diff --git a/request/request.go b/request/request.go
index 105cd8528..52bf8629b 100644
--- a/request/request.go
+++ b/request/request.go
@@ -194,7 +194,7 @@ func (r *Request) Size() int {
// SizeAndDo adds an OPT record that the reflects the intent from request.
// The returned bool indicated if an record was found and normalised.
func (r *Request) SizeAndDo(m *dns.Msg) bool {
- o := r.Req.IsEdns0() // TODO(miek): speed this up
+ o := r.Req.IsEdns0()
if o == nil {
return false
}
@@ -208,6 +208,10 @@ func (r *Request) SizeAndDo(m *dns.Msg) bool {
mo.SetUDPSize(o.UDPSize())
mo.Hdr.Ttl &= 0xff00 // clear flags
+ if len(o.Option) > 0 {
+ o.Option = supportedOptions(o.Option)
+ }
+
if odo {
mo.SetDo()
}
@@ -219,6 +223,10 @@ func (r *Request) SizeAndDo(m *dns.Msg) bool {
o.SetVersion(0)
o.Hdr.Ttl &= 0xff00 // clear flags
+ if len(o.Option) > 0 {
+ o.Option = supportedOptions(o.Option)
+ }
+
if odo {
o.SetDo()
}
@@ -305,7 +313,6 @@ func (r *Request) Scrub(reply *dns.Msg) *dns.Msg {
}
if rl <= size {
- r.SizeAndDo(reply)
return reply
}
@@ -341,7 +348,6 @@ func (r *Request) Scrub(reply *dns.Msg) *dns.Msg {
// this extra m-1 step does make it fit in the client's buffer however.
}
- r.SizeAndDo(reply)
reply.Truncated = true
return reply
}
diff --git a/request/request_test.go b/request/request_test.go
index 5e814f76e..4411c6a82 100644
--- a/request/request_test.go
+++ b/request/request_test.go
@@ -123,10 +123,6 @@ func TestRequestScrubExtraEdns0(t *testing.T) {
if reply.Truncated {
t.Errorf("Want scrub to not set truncated bit")
}
- opt := reply.Extra[len(reply.Extra)-1]
- if opt.Header().Rrtype != dns.TypeOPT {
- t.Errorf("Last RR must be OPT record")
- }
}
func TestRequestScrubExtraRegression(t *testing.T) {
@@ -153,10 +149,6 @@ func TestRequestScrubExtraRegression(t *testing.T) {
if reply.Truncated {
t.Errorf("Want scrub to not set truncated bit")
}
- opt := reply.Extra[len(reply.Extra)-1]
- if opt.Header().Rrtype != dns.TypeOPT {
- t.Errorf("Last RR must be OPT record")
- }
}
func TestTruncation(t *testing.T) {
diff --git a/request/writer.go b/request/writer.go
index ffbbe93e3..67be53ebb 100644
--- a/request/writer.go
+++ b/request/writer.go
@@ -15,6 +15,8 @@ func NewScrubWriter(req *dns.Msg, w dns.ResponseWriter) *ScrubWriter { return &S
// scrub on the message m and will then write it to the client.
func (s *ScrubWriter) WriteMsg(m *dns.Msg) error {
state := Request{Req: s.req, W: s.ResponseWriter}
+
n := state.Scrub(m)
+ state.SizeAndDo(n)
return s.ResponseWriter.WriteMsg(n)
}
/main&id=61901306266fac82e7121ea93fde6c8ffb5826bb&follow=1'>[resolver] Stripe `file://` from import pathsGravatar Jarred Sumner 2-5/+17 2022-07-11Fixes https://github.com/oven-sh/bun/issues/195Gravatar Jarred Sumner 3-3/+70 2022-07-11Revert "Fix: NotSameFileSystem at clonefile (#546)" (#581)Gravatar Jarred Sumner 1-1/+1 This reverts commit 2659febd1b74e8215ff7dbfb2d1b19f4b4f8a71a. 2022-07-11feat(types): Add types for node modules and various fixing (#470)Gravatar Snazzah 24-60/+23551 * fix(types): add __dirname and __filename as deprecated types * fix(types): add stream() method to Blob * fix(types): update getRandomValues in Crypto * fix(types): add buffer type defs * fix(types): remove buffer type setting in fs * fix(types): extend TypedArray in crypto.getRandomValues Co-authored-by: Carter Snook <cartersnook04@gmail.com> * fix(types): add notes to some buffer methods * fix(types): remove since jsdoc comments from buffer * chore(types): fix bundle script and build types * fix(types): update bundle script This really shouldn't do anything differently, but it no longer hangs whenever I bundle types. Not sure if anyone else has this problem but, ehhhh... * fix(types): remove unused types in buffer * feat(types): add assert module types * feat(types): add events module types * feat(types): add os module types * feat(types): add domain module types * fix(types): add process.isBun type * feat(types): add util module types * feat(types): add querystring module types * feat(types): add process module types * feat(types): add string_decoder module types * feat(types): add sys module types * feat(types): add timers module types * feat(types): add stream module types * feat(types): add crypto module types fix(types): fix types for stream, timers and util modules * feat(types): add constants module types * feat(types): add url module types * feat(types): add tty module types * feat(types): add http module types * feat(types): add https module types * feat(types): add punycode module types * feat(types): add zlib module types * feat(types): add supports-color module types Co-authored-by: Carter Snook <cartersnook04@gmail.com> 2022-07-11fix: environment typo (#568)Gravatar Carlos Gabriel Vilas Novas Soares 1-3/+3 2022-07-11Cleanup discord-interactions readme (#451)Gravatar CharlieS1103 1-1/+1 2022-07-11Fix: NotSameFileSystem at clonefile (#546)Gravatar Aditya Gupta 1-1/+1 Fixes issue #531 Before this, using 'bun install' on a directory in different filesystem such as tmpfs (/tmp) would have caused "Error: NotSameFileSystem". This commit fixes that by handling this error, and at end of function it will fall back to use copyfile (same as --backend=copyfile) 2022-07-11Updated typo in example (#573)Gravatar rml1997 1-2/+2 Changed deocder to decoder 2022-07-11Fixes https://github.com/oven-sh/bun/issues/561Gravatar Jarred Sumner 3-14/+56 2022-07-11[js] Include TypedArray type name for empty arraysGravatar Jarred Sumner 1-16/+16 2022-07-11[js] When `console.log` typed arrays, include the type name and limit ↵Gravatar Jarred Sumner 1-12/+17 printed count to 512 2022-07-11Fixes https://github.com/oven-sh/bun/issues/229Gravatar Jarred Sumner 4-6/+56 2022-07-11Bump zig buildGravatar Jarred Sumner 1-1/+1 2022-07-11Move symbolGravatar Jarred Sumner 1-3/+7 2022-07-11Run prettierGravatar Jarred Sumner 1-10/+25 2022-07-11Fix broken buildGravatar Jarred Sumner 1-1/+1 2022-07-11[bun wiptest] Fix copyGravatar Jarred Sumner 1-1/+1 2022-07-11add depd browser polyfill (#517)Gravatar evan 2-0/+89 2022-07-11Fix macOS build (#525)Gravatar thislooksfun 3-94/+103 * style: remove some trailing whitespace * docs: make `identifier-cache` _before_ `jsc` Running them the other way around results in a failed build. * docs: `npm i` in both `test/snippets` _and_ `test/scripts` `test/scripts` has node packages as well. If they aren't installed, then some of the tests fail to start. * docs: add `rust` to list of homebrew packages One of the dependencies tries to run `cargo`, and will fail the build if it can't. The `cargo` command is provided by the `rust` brew package. * docs: clean up section on macOS code signing This requirement applies to _all_ macOS builds, not just those on Apple Silicon, and also had some slightly confusing wording. * build: remove leading whitespace from flags This leading whitespace was making my system treat the argument as a file with name ` -L$(LLVM_PREFIX)/lib` (leading whitespace included), instead of as a library path argument. * build: try llvm@13 first, then fall back on bare llvm The macOS instructions say to install `llvm@13`, which has a different path than the bare `llvm` install (`brew --prefix llvm@13` != `brew --prefix llvm`). This patch takes a slightly smarter approach: 1. If the user defined `LLVM_PREFIX` and it points to a valid path on disk, use that. 2. If `LLVM_PREFIX` is NOT a valid path, try setting it to the `llvm@13` path. 3. If it's STILL not a valid path, try the plain `llvm` path 4. If it's STILL not valid, set it to a user-friendly error. There might be a better solution for doing this, I'm not well-versed in Makefile syntax, but it's at least slightly better than it was before. * fix(build): update cast signature `std.math.cast` was changed in 0e6285c8fc31ff866df96847fe34e660da38b4a9. It used to throw if the cast would overflow, but now it returns `null` instead. 2022-07-10Update GitHub URL to match new repo URL (#547)Gravatar Aurora Luna Takemi 22-47/+47 * Update repo URLs * GitHub URL update * Revert accidental URL changes 2022-07-10chore(feature-request): change feature request to enhancementGravatar Hyro 1-1/+1 2022-07-10chore(api-ref-docs): change doc to documentationGravatar Hyro 1-1/+1 2022-07-10chore(bug-report): add label bug, need reproGravatar Hyro 1-0/+1