Add support for TRUNCATED DNSSEC status#1595
Merged
Merged
Conversation
…ncated answer can't be validated. If this is an answer to a DNSSEC-generated query, we still need to get the client to retry over TCP, so we return an answer with the TC bit set, even if the actual answer fits into buffer. All the other code is already there, just the display code needs addition. Signed-off-by: DL6ER <dl6er@dl6er.de>
yubiuser
approved these changes
Jul 24, 2023
yubiuser
left a comment
Member
There was a problem hiding this comment.
Needs to be added to https://docs.pi-hole.net/database/ftl/#dnssec-status as well
Member
Author
|
Pushed as d3f7681pi-hole/docs@5027b84 |
5 tasks
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this implement/fix?
Add
TRUNCATEDstatus to enumeration of valid DNSSEC status codes. Truncated answer can't be validated. If this is an answer to a DNSSEC-generated query, we still need to get the client to retry over TCP, so we return an answer with theTCbit set, even if the actual answer fits into buffer. All the other code is already there, just the parsing code needs a minor tweak.I have never seen a truncated DNSSEC message with my local
unbound, however, I have recently received comments about this status popping up quite often with certain online resolvers (Quad9 or DNS.Watch IIRC) putting too much optional content into the DNSSEC reply causing fragmentation (= truncation). The only way to remedy is retrying over TCP which then does support fragmentation (as said above).This fix is merely cosmetic, FTL already behaves correctly but is needlessly complaining about an unknown status in its log file.
Related issue or feature (if applicable): N/A
Pull request in docs with documentation (if applicable): N/A
By submitting this pull request, I confirm the following:
git rebase)Checklist:
developmentalbranch.