houyuwushang
98bdb44f4d
plugin/hosts: make unsupported type fallthrough opt-in ( #8282 )
2026-07-19 19:59:12 -07:00
Yong Tang
201d86a098
core: Add connection-level concurrency limiting to DNS-over-QUIC ( #8213 )
...
* core: Add connection-level concurrency limiting to DNS-over-QUIC
This PR adds max connections to prevent unbounded connection goroutine growth
for DoQ
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Add test to cover change
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-19 03:52:42 -07:00
Ville Vesilehto
077774e0cd
ci: run plugin tests on Windows ( #8314 )
...
Plugin package tests previously ran only on Linux, so Windows-
specific failures were never caught. Run them in CI and make the
affected tests portable across platforms.
Signed-off-by: Ville Vesilehto <ville@vesilehto.fi >
2026-07-19 03:52:23 -07:00
Yong Tang
96ec17d5c6
plugin/forward: Fix incorrect retry of local DNS message serialization failures ( #8313 )
...
This PR fixes the forward plugin incorrectly retrying deterministic
local DNS message serialization failures as if they were upstream transport errors.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-19 03:48:00 -07:00
Ville Vesilehto
57f73b4a43
Merge commit from fork
...
Ensure DoH, DoH3, DoQ, and DNS-over-gRPC continue to reject RFC 2136
UPDATE requests before dispatch. This guards the common request
acceptance policy across every affected transport.
Signed-off-by: Ville Vesilehto <ville@vesilehto.fi >
2026-07-18 20:36:05 -07:00
Ville Vesilehto
c1fe47bc3a
test(tls): make keylog path test portable ( #8311 )
...
Directory permission checks can be bypassed by privileged users and may
behave differently on filesystems with nonstandard permission semantics.
Make the bad-path case deterministic so TLS keylog tests remain portable
across supported environments.
Signed-off-by: Ville Vesilehto <ville@vesilehto.fi >
2026-07-18 20:11:48 -07:00
Ncesam
e1f4d0cb90
plugin/rewrite: normalize exact cname rewrite targets and preserve all records ( #8285 )
...
Signed-off-by: ncesam <rybushkin09@bk.ru >
2026-07-15 18:06:03 -07:00
Ncesam
99b683aa41
plugin/transfer: collect all notify errors instead of shadowing ( #8283 )
...
* plugin/transfer: collect all notify errors instead of shadowing
Signed-off-by: ncesam <rybushkin09@bk.ru >
* plugin/transfer: add regression test for notify multiple failures
Signed-off-by: ncesam <rybushkin09@bk.ru >
---------
Signed-off-by: ncesam <rybushkin09@bk.ru >
2026-07-15 18:05:01 -07:00
Ville Vesilehto
530b0a5ff2
Merge commit from fork
...
DoH, DoQ, and DNS-over-gRPC unpack messages without the acceptance
checks used by UDP and TCP. An unauthenticated request with a large
QDCOUNT can therefore force excessive allocations while names are
decoded and exhaust server memory.
Enforce the same request policy across all server transports.
Signed-off-by: Ville Vesilehto <ville@vesilehto.fi >
2026-07-15 17:54:46 -07:00
dependabot[bot]
d5e54040ff
build(deps): bump the go-etcd-io group with 2 updates ( #8292 )
...
Bumps the go-etcd-io group with 2 updates: [go.etcd.io/etcd/api/v3](https://github.com/etcd-io/etcd ) and [go.etcd.io/etcd/client/v3](https://github.com/etcd-io/etcd ).
Updates `go.etcd.io/etcd/api/v3` from 3.6.12 to 3.6.13
- [Release notes](https://github.com/etcd-io/etcd/releases )
- [Commits](https://github.com/etcd-io/etcd/compare/v3.6.12...v3.6.13 )
Updates `go.etcd.io/etcd/client/v3` from 3.6.12 to 3.6.13
- [Release notes](https://github.com/etcd-io/etcd/releases )
- [Commits](https://github.com/etcd-io/etcd/compare/v3.6.12...v3.6.13 )
---
updated-dependencies:
- dependency-name: go.etcd.io/etcd/api/v3
dependency-version: 3.6.13
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: go-etcd-io
- dependency-name: go.etcd.io/etcd/client/v3
dependency-version: 3.6.13
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: go-etcd-io
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 23:03:41 +03:00
dependabot[bot]
a1aef3a70f
build(deps): bump github.com/aws/aws-sdk-go-v2/config ( #8294 )
...
Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) from 1.32.26 to 1.32.28.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.26...config/v1.32.28 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-version: 1.32.28
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 23:02:51 +03:00
dependabot[bot]
04280acbf4
build(deps): bump github.com/aws/aws-sdk-go-v2/credentials ( #8299 )
2026-07-15 12:15:08 -07:00
dependabot[bot]
8fe5801bf1
build(deps): bump google.golang.org/api from 0.280.0 to 0.287.1 ( #8295 )
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.280.0 to 0.287.1.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.280.0...v0.287.1 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-version: 0.287.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 07:30:23 -07:00
dependabot[bot]
621eb4d05b
build(deps): bump github.com/aws/aws-sdk-go-v2/service/secretsmanager ( #8301 )
...
Bumps [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2 ) from 1.42.4 to 1.43.0.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/amp/v1.42.4...service/s3/v1.43.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
dependency-version: 1.43.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 07:29:59 -07:00
dependabot[bot]
751e0c25e7
build(deps): bump github.com/aws/aws-sdk-go-v2/feature/ec2/imds ( #8303 )
...
Bumps [github.com/aws/aws-sdk-go-v2/feature/ec2/imds](https://github.com/aws/aws-sdk-go-v2 ) from 1.18.29 to 1.18.30.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.29...config/v1.18.30 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/feature/ec2/imds
dependency-version: 1.18.30
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 07:29:35 -07:00
dependabot[bot]
92f677c89c
build(deps): bump github.com/pires/go-proxyproto from 0.13.0 to 0.14.0 ( #8304 )
...
Bumps [github.com/pires/go-proxyproto](https://github.com/pires/go-proxyproto ) from 0.13.0 to 0.14.0.
- [Release notes](https://github.com/pires/go-proxyproto/releases )
- [Commits](https://github.com/pires/go-proxyproto/compare/v0.13.0...v0.14.0 )
---
updated-dependencies:
- dependency-name: github.com/pires/go-proxyproto
dependency-version: 0.14.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 07:29:03 -07:00
dependabot[bot]
ccc7745f2e
build(deps): bump sigs.k8s.io/mcs-api from 0.5.0 to 0.5.1 ( #8308 )
...
Bumps [sigs.k8s.io/mcs-api](https://github.com/kubernetes-sigs/mcs-api ) from 0.5.0 to 0.5.1.
- [Release notes](https://github.com/kubernetes-sigs/mcs-api/releases )
- [Changelog](https://github.com/kubernetes-sigs/mcs-api/blob/master/RELEASE.md )
- [Commits](https://github.com/kubernetes-sigs/mcs-api/compare/v0.5.0...v0.5.1 )
---
updated-dependencies:
- dependency-name: sigs.k8s.io/mcs-api
dependency-version: 0.5.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 07:28:39 -07:00
dependabot[bot]
f76b78c8a9
build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.42.0 to 1.42.1 ( #8305 )
...
Bumps [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) from 1.42.0 to 1.42.1.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.42.0...v1.42.1 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-version: 1.42.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 17:02:55 +03:00
dependabot[bot]
9d831348f9
build(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.2 ( #8297 )
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from 8.2.0 to 8.3.2.
- [Release notes](https://github.com/astral-sh/setup-uv/releases )
- [Commits](fac544c07d...11f9893b08 )
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 8.3.2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 17:02:41 +03:00
dependabot[bot]
36e802a6df
build(deps): bump docker/login-action from 4.2.0 to 4.4.0 ( #8298 )
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 4.2.0 to 4.4.0.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](650006c6eb...af1e73f918 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: 4.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 17:02:25 +03:00
dependabot[bot]
c6191e2bf1
build(deps): bump github.com/aws/aws-sdk-go-v2/service/route53 ( #8307 )
...
Bumps [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2 ) from 1.63.4 to 1.64.0.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/ecs/v1.63.4...service/s3/v1.64.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/route53
dependency-version: 1.64.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 17:01:38 +03:00
dependabot[bot]
2bff8bb74e
build(deps): bump github/codeql-action/upload-sarif ( #8296 )
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:54:25 +03:00
dependabot[bot]
f4e55c166e
build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0 ( #8300 )
...
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:54:01 +03:00
dependabot[bot]
035b553840
build(deps): bump github/codeql-action/autobuild from 4.36.2 to 4.37.0 ( #8293 )
...
Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:53:38 +03:00
dependabot[bot]
6829a7308f
build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.0 ( #8302 )
...
Bumps [github/codeql-action/init](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:52:58 +03:00
Yong Tang
18a58b9e89
plugin/acl: Fix autopath from bypassing acl checks ( #8290 )
...
This fix prevents CoreDNS `autopath` from bypassing `acl` checks
when it rewrites an allowed query into a name within an ACL-protected zone.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-14 22:36:06 -07:00
Yong Tang
1ba14119d0
plugin/acl: Fix blocked clients from receiving cached DNS answers ( #8289 )
...
This PR fixes plugin ordering so ACL checks run before cache lookups,
preventing blocked clients from receiving cached DNS answers populated by allowed clients
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-14 22:26:49 -07:00
houyuwushang
7cd99da013
plugin/secondary: reset catalog members on ID change ( #8281 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-07-14 18:51:12 -07:00
Yong Tang
5131b8f944
plugin/proxyproto: Apply an explicitly configured default policy evenwhen no allow list is present. ( #8278 )
...
* plugin/proxyproto: Apply an explicitly configured default policy even when no allow list is present.
This PR fix the issue where explicitly configured default reject policy
is ignoreed when no allo list is present
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* golint fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-13 17:34:30 -07:00
Yong Tang
e16e829181
plugin/forward: Fix issue in DoH health checks used a default TLS instead of the configured CA ( #8279 )
...
This PR fixes issue in forward plugin where default TLS instead of
configured CA was used.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-13 17:34:18 -07:00
Yong Tang
4ebf66a74e
plugin/forward: Fix incorrect failover counter reset ( #8277 )
...
* plugin/forward: Fix incorrect failover counter reset
This PR fixes the isseue where resetting the failover counter caused
retry the same upstreams until timeout instead of stopping after one pass.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* golint fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-13 17:34:06 -07:00
Yong Tang
e5053d50ad
plugin/file: Fix panic on zero-valued SOA refresh ( #8276 )
...
This PR fixes panic with zero-valued SOA refresh
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-13 17:33:51 -07:00
Omkhar Arasaratnam
38e26f25c4
plugin/file: do not expand wildcard across a closer empty non-terminal ( #8223 )
...
A query for a name that sits below a closer empty non-terminal was wrongly
answered with a shallower wildcard record instead of NXDOMAIN. Per RFC 4592
2.2.1 a wildcard is the source of synthesis only when the wildcard owner's
parent is the closest encloser of the queried name; if an empty non-terminal
exists between that parent and the queried name, it is the closer encloser and
the shallower wildcard must not be expanded.
Guard the wildcard expansion in Zone.Lookup with closerENTExists, which walks
the strict ancestors of the queried name between the wildcard parent and the
name and reports whether any of them is an empty non-terminal.
Adds TestLookupWildcardRespectsCloserEmptyNonTerminal, which asserts NXDOMAIN
for a name below a closer empty non-terminal and keeps a no-regression case
where a plain wildcard with no closer empty non-terminal still applies.
Signed-off-by: Omkhar Arasaratnam <omkhar@linkedin.com >
Co-authored-by: Omkhar Arasaratnam <omkhar@linkedin.com >
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-11 03:03:52 -07:00
Nikolaus Schuetz
af1e34ebc8
test: poll instead of fixed sleeps across several tests ( #8275 )
...
Several tests slept a fixed duration then took a single snapshot of an
async result, racing whatever they waited on:
- forward health tests waited 20ms for the health-check goroutine to bump
an atomic counter,
- the auto plugin tests (dns + metrics) waited 50-110ms for a file-watch
reload to be picked up,
- the file ZoneReload test waited 30ms (self-described as could still be
racy) for a reload,
- the overloaded health test slept 1s for its background goroutine to fire
its first request.
Replace each with a bounded poll of the actual condition (the atomic
counter, a dns.Exchange response, a metrics scrape, z.ApexIfDefined, or a
channel signalled by the test's own handler) so they pass as soon as the
awaited state is reached and no longer flake when it is slower than the
fixed wait. Test-only.
Signed-off-by: Nikolaus Schuetz <nikolauspschuetz@gmail.com >
2026-07-10 15:20:57 -07:00
houyuwushang
6ec70a0603
request/cache: bind responses and entries to QCLASS ( #8272 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-07-10 15:18:27 -07:00
Yong Tang
2d42f0e8f5
Enforce doker build test ( #8271 )
...
This PR enforce docker-build test so that every PR will check to make
sure the docker build (which reliesd on if base image, binary, etc
are still correct), is actually available and working.
Note previously, we only check a dry run of docker push, but not actually
build the docker image (as binary was fetched from release version on github).
This PR fetch local binary build instead as there maynot be the same in different
release versions of binary.
This is related 8228
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-10 00:24:39 -07:00
Yong Tang
39a48acf6b
Change base image for mips64le ( #8270 )
...
Since mips64le does not have a distroless image anymore, have to change the base
image.
This is part of 8228. However, since it only involved container image and
not rebuild binary, shoud be ok with existing one.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-09 23:54:07 -07:00
Yong Tang
424d125775
Update release note of 1.14.6 ( #8269 )
...
This PR update release note of 1.14.6, part of 8228
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
v1.14.6
2026-07-09 22:04:35 -07:00
Yong Tang
568a4ec697
Populating errors from all Makefile ( #8268 )
...
THis PR populating errors from all Makefile, so any PR test can
be fully checked correctly. See #8265 for releated issue
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-09 22:04:24 -07:00
Yong Tang
7660f4c541
Bump version to 1.14.6 ( #8267 )
...
This PR bumps version to 1.14.6, part of 8228
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-09 21:32:01 -07:00
Yong Tang
886bb85849
Test: populating build test failure ( #8265 )
...
* Test: populating build test failure
The current build test won't populating the failure caused issue undetected:
See https://github.com/coredns/coredns/issues/8228#issuecomment-4931425842
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Pupulate error from Makefile
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2026-07-09 21:12:49 -07:00
Ville Vesilehto
99bad66253
chore(deps): downgrade dd-trace-go to v2.8.2 ( #8266 )
...
dd-trace-go versions >=2.9.0 do not compile without warnings
on non-64-bit architectures. Downgrade to v2.8.2 until upstream
fixes the issue.
Signed-off-by: Ville Vesilehto <ville@vesilehto.fi >
2026-07-09 20:50:43 -07:00
Immanuel Tikhonov
5cab9853cd
fix(auto): keep first matching zone file for duplicate origins ( #8216 )
...
Signed-off-by: immanuwell <pchpr.00@list.ru >
2026-07-09 17:43:07 -07:00
houyuwushang
1e01c0ad7c
plugin/secondary: serve catalog member zones ( #8230 )
...
Signed-off-by: houyuwushang <liuluoqianqiu@outlook.com >
2026-07-09 17:42:30 -07:00
Filippo125
e4990abfa3
feat(forward): add source_address directive ( #8011 )
...
* fix(dnssec): avoid caching empty signing results (#7996 )
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* save only
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* do #8008
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Fix Address used if tcp
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Fix bad using of dialer type
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* core: Add full TSIG verification in gRPC transport (#8006 )
* core: Add full TSIG verification in gRPC transport
This PR add full TSIG verification in gRPC using dns.TsigVerify() so invalid signatures and timestamps are correctly detected instead of only checking key presence.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* core: Add full TSIG verification in QUIC transport (#8007 )
* core: Add full TSIG verification in QUIC transport
This PR add full TSIG verification in QUIC using dns.TsigVerify()
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
* Fix
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
---------
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix(test): deduplicate TSIG test helpers (#8009 )
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix(dnssec): return nil sigs on sign error (#7999 )
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix(dnssec): return nil from ParseKeyFile on error (#8000 )
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix(dnsserver): allow view server blocks in any declaration order (#8001 )
When using the view plugin, filtered and unfiltered server blocks can
share the same zone and port. The zone overlap validation rejected this
configuration when the unfiltered block was not declared last, because
filtered configs treated an already-registered zone as an error.
Skip the 'already defined' check for configs that have filter functions,
since they are expected to coexist with an unfiltered catch-all block on
the same zone/port.
Fixes #7733
Signed-off-by: umut-polat <52835619+umut-polat@users.noreply.github.com >
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix(doh): use per-connection local address for PROXY protocol (#8005 )
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix(transfer): batch AXFR records by message size instead of count (#8002 )
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix(tls): use temp dir for keylog test path (#8010 )
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Rename local_address option to source_address
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Rename local_address also in readme
Add test
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Resolve change request in pr
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix ci lint
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Improve doc on source_address routing needs
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Remove added timeout
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* add use of source address also for health check query
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* remove untrailing newline from health_test.go
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix file format
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Update plugin/forward/setup_test.go
Co-authored-by: Ville Vesilehto <ville@vesilehto.fi >
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Remove dead code in TestHealthLocalAddress
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Fix misspelling
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* Try to set default timeout
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
* fix format in health.go
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
---------
Signed-off-by: Filippo <filippo.ferrazini@gmail.com >
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
Signed-off-by: umut-polat <52835619+umut-polat@users.noreply.github.com >
Co-authored-by: Ville Vesilehto <ville@vesilehto.fi >
Co-authored-by: Yong Tang <yong.tang.github@outlook.com >
Co-authored-by: Umut Polat <52835619+umut-polat@users.noreply.github.com >
Co-authored-by: Cedric Wang <wangzongqi@msn.com >
2026-07-09 17:38:22 -07:00
Yong Tang
adba3b3703
Update Release Note 1.14.5 ( #8264 )
...
This PR Update Release Note for 1.14.5 (See 8228)
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
v1.14.5
2026-07-09 16:49:26 -07:00
Ilya Kulakov
540e2f325f
plugin/tsig: don't echo client's TSIG.Error if verification is successful ( #8215 )
2026-07-09 15:04:23 -07:00
Ville Vesilehto
0ebe4da2b0
docs(timeouts): document DoQ read timeout ( #8263 )
2026-07-09 15:01:59 -07:00
Ville Vesilehto
6d13ab20af
chore: update release notes for 1.14.5 ( #8262 )
2026-07-09 15:01:31 -07:00
Pavel Lazureykis
974d693e6f
plugin/dnstap: fix self-deadlock in listener broadcast on client flush error ( #8260 )
...
listener.Dnstap holds clientsMu.RLock() while iterating connected sink
clients. In the flush-error branch it called removeClient(c) synchronously,
but removeClient takes clientsMu.Lock(). A sync.RWMutex is not reentrant, so
the goroutine blocks forever waiting to acquire the write lock it can never
get while holding the read lock. The queued Lock() then blocks every
subsequent Dnstap broadcast and close(), and the goroutine leaks.
A flush error is the normal failure mode for a slow or disconnected sink
client (writeMsg buffers into framestream and succeeds; flush does the real
socket write and fails), so a single misbehaving client wedged the whole
listen path. Because Dnstap runs inline in the request-serving goroutine via
TapMessageWithMetadata, this could cascade into stalled request handling.
The write-error branch one line up already offloaded with `go removeClient(c)`.
Do the same in the flush-error branch and drop the early return so the
broadcast still reaches the remaining clients.
Assisted-by: Claude Opus 4.8
Signed-off-by: Pavel Lazureykis <pavel@lazureykis.dev >
2026-07-09 20:43:35 +03:00