fix(network): reject non-stub DNS traffic#6
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
v4.2.7修复了sing-box不支持type: "dns"inbound 导致的容器启动失败,但线上继续推进到网络校验后失败在net.dns_leak:dig @8.8.8.8被无条件hijack-dns规则接管并成功返回。修改
hijack-dns限定为只匹配本地 DNS stub inbound:inbound: "dns-direct"。dig @8.8.8.8)失败。CHANGELOG.md的v4.2.8条目和 GSD quick 记录。验证
go test ./internal/network -run TestBuildContainerSingBoxConfig_DNSHijackScopedToStubAndRejectsOtherDNS -count=1在修复前失败。go test ./internal/network -run TestBuildContainerSingBoxConfig_DNSHijackScopedToStubAndRejectsOtherDNS -count=1go test ./internal/network -count=1go test ./internal/network ./internal/runtime/tasks ./internal/controlplane/http -count=1go test ./... -count=1dig @8.8.8.8 example.com返回非零退出码,普通getent ahostsv4 example.com正常。