mirror of
				https://github.com/coredns/coredns.git
				synced 2025-10-31 02:03:20 -04:00 
			
		
		
		
	Fix EDNS0 compliance (#2357)
* Fix EDNS0 compliance Do SizeAndDo in the server (ScrubWriter) and remove all uses of this from the plugins. Also *always* do it. This is to get into compliance for https://dnsflagday.net/. The pkg/edns0 now exports the EDNS0 options we understand; this is exported to allow plugins add things there. The *rewrite* plugin used this to add custom EDNS0 option codes that the server needs to understand. This also needs a new release of miekg/dns because it triggered a race-condition that was basicly there forever. See: * https://github.com/miekg/dns/issues/857 * https://github.com/miekg/dns/pull/859 Running a test instance and pointing the https://ednscomp.isc.org/ednscomp to it shows the tests are now fixed: ~~~ EDNS Compliance Tester Checking: 'miek.nl' as at 2018-12-01T17:53:15Z miek.nl. @147.75.204.203 (drone.coredns.io.): dns=ok edns=ok edns1=ok edns@512=ok ednsopt=ok edns1opt=ok do=ok ednsflags=ok docookie=ok edns512tcp=ok optlist=ok miek.nl. @2604:1380:2002:a000::1 (drone.coredns.io.): dns=ok edns=ok edns1=ok edns@512=ok ednsopt=ok edns1opt=ok do=ok ednsflags=ok docookie=ok edns512tcp=ok optlist=ok All Ok Codes ok - test passed. ~~~ Signed-off-by: Miek Gieben <miek@miek.nl> Signed-off-by: Miek Gieben <miek@miek.nl> * typos in comments Signed-off-by: Miek Gieben <miek@miek.nl>
This commit is contained in:
		
							
								
								
									
										31
									
								
								request/edns0.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										31
									
								
								request/edns0.go
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,31 @@ | ||||
| package request | ||||
|  | ||||
| import ( | ||||
| 	"github.com/coredns/coredns/plugin/pkg/edns" | ||||
|  | ||||
| 	"github.com/miekg/dns" | ||||
| ) | ||||
|  | ||||
| func supportedOptions(o []dns.EDNS0) []dns.EDNS0 { | ||||
| 	var supported = make([]dns.EDNS0, 0, 3) | ||||
| 	// For as long as possible try avoid looking up in the map, because that need an Rlock. | ||||
| 	for _, opt := range o { | ||||
| 		switch code := opt.Option(); code { | ||||
| 		case dns.EDNS0NSID: | ||||
| 			fallthrough | ||||
| 		case dns.EDNS0EXPIRE: | ||||
| 			fallthrough | ||||
| 		case dns.EDNS0COOKIE: | ||||
| 			fallthrough | ||||
| 		case dns.EDNS0TCPKEEPALIVE: | ||||
| 			fallthrough | ||||
| 		case dns.EDNS0PADDING: | ||||
| 			supported = append(supported, opt) | ||||
| 		default: | ||||
| 			if edns.SupportedOption(code) { | ||||
| 				supported = append(supported, opt) | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	return supported | ||||
| } | ||||
		Reference in New Issue
	
	Block a user