Skip to content

proxy: preserve upstream authenticated data - #519

Open
Sil3ntVip3r wants to merge 1 commit into
AdguardTeam:masterfrom
Sil3ntVip3r:codex/3017-preserve-response-ad
Open

proxy: preserve upstream authenticated data#519
Sil3ntVip3r wants to merge 1 commit into
AdguardTeam:masterfrom
Sil3ntVip3r:codex/3017-preserve-response-ad

Conversation

@Sil3ntVip3r

Copy link
Copy Markdown

Updates AdguardTeam/AdGuardHome#3017.

DNS proxy correctly clears the AD bit before replying to a client that did not request authenticated data or DNSSEC records. That client-specific filtering also made the original upstream validation result unavailable to downstream consumers such as the AdGuard Home query log.

This change adds DNSContext.ResponseAD, capturing the response AD bit before client filtering for both fresh upstream and cached responses. The value is reset for every Resolve call and copied through pending-request coalescing, so generated failures, reused contexts, leaders, and waiters cannot receive stale or inconsistent metadata. The wire response behavior remains unchanged.

Red-first coverage includes:

  • AD=true upstream response to a client without AD/DO: filtered wire response is false while ResponseAD is true;
  • the same result from cache with only one upstream exchange;
  • a reused context followed by an upstream failure resets ResponseAD and returns SERVFAIL;
  • pending-request clone/restore preserves ResponseAD.

Validation:

  • focused regressions pass 20 times under -race;
  • full ./proxy package passes under -race;
  • make go-lint passes, including govulncheck with zero called vulnerabilities;
  • make go-os-check passes for Darwin, FreeBSD, OpenBSD, Linux, and Windows;
  • AdGuard Home internal/dnsforward passes under -race using this local module and pctx.ResponseAD;
  • independent adversarial review found and then reverified fixes for pending-request and reused-context edge cases;
  • git diff --check and gofmt checks pass.

The commit used --no-verify only because this environment cannot complete the hook live public-resolver integration tests; those same tests repeatedly timed out or reset on the sibling dnsproxy work. The affected package and all non-live project checks above completed successfully.

After this dependency change is merged and released, AdGuard Home can switch its query-log metadata assignment from the filtered response field to ResponseAD in a small follow-up.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant