resolved: always return the validated answers when validating#31952
Merged
yuwata merged 1 commit intosystemd:mainfrom Mar 27, 2024
Merged
resolved: always return the validated answers when validating#31952yuwata merged 1 commit intosystemd:mainfrom
yuwata merged 1 commit intosystemd:mainfrom
Conversation
bluca
approved these changes
Mar 26, 2024
yuwata
reviewed
Mar 26, 2024
Member
|
Is it possible to add a test case for this? Or already tested? cc @mrc0mmand |
cd588a7 to
4e81543
Compare
yuwata
reviewed
Mar 26, 2024
We normally expect sd-resolved only to return the validated subset of a validated response. In some cases we give up on validating, because we have enough information already to conclude the answer is bogus. Let's be sure to always reply with only the validated subset in these cases too, so that we don't return bogus answers and confuse primitive clients that won't see the SERVFAIL rcode.
4e81543 to
19d7f01
Compare
Contributor
Author
I don't think there is a test atm. The domains I used to test this are |
poettering
reviewed
Apr 11, 2024
Member
|
Hmm, I wonder if it wouldn#t be better to simply clear the answer structure in dns_transaction_complete() for all result codes that aren't a success. Seems cleaner to me, as it would cover all result codes. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
We normally expect sd-resolved only to return the validated subset of a validated response. In some cases we give up on validating, because we have enough information already to conclude the answer is bogus.
Let's be sure to always reply with only the validated subset in these cases too, so that we don't return bogus answers and confuse primitive clients that won't see the SERVFAIL rcode.
Fixes: #24827 #32238