mirror of
https://github.com/hickory-dns/hickory-dns.git
synced 2026-04-25 11:15:54 +03:00
[PR #2119] [MERGED] Bailiwick checking for the recursor #2822
Labels
No labels
blocked
breaking-change
bug
bug:critical
bug:tests
cleanup
compliance
compliance
compliance
crate:all
crate:client
crate:native-tls
crate:proto
crate:recursor
crate:resolver
crate:resolver
crate:rustls
crate:server
crate:util
dependencies
docs
duplicate
easy
easy
enhance
enhance
enhance
feature:dns-over-https
feature:dns-over-quic
feature:dns-over-tls
feature:dnsssec
feature:global_lb
feature:mdns
feature:tsig
features:edns
has workaround
ops
perf
platform:WASM
platform:android
platform:fuchsia
platform:linux
platform:macos
platform:windows
pull-request
question
test
tools
tools
trust
unclear
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/hickory-dns#2822
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/hickory-dns/hickory-dns/pull/2119
Author: @marcus0x62
Created: 12/27/2023
Status: ✅ Merged
Merged: 1/5/2024
Merged by: @bluejekyll
Base:
main← Head:bailiwick_checking📝 Commits (4)
fab156cBasic bailiwick checking for the recursor6d1da5cChange in_bailiwick function name to be more descriptive (is_subzone)e73d6dbChanged to doc comment9163288Refactor is_subzone to use Name::zone_of with additional checks for partially/fully qualified domains.📊 Changes
1 file changed (+109 additions, -1 deletions)
View changed files
📝
crates/recursor/src/recursor.rs(+109 -1)📄 Description
This PR improves cache poisoning resistance in the recursor by adding Bailiwick checking: for records returned from a remote resolver, the bailiwick check tests that the records are subordinate to the zone authority: example.com can return records for host.example.com, but host.otherdomain.com is out of bailiwick and rejected.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.