Skip to content

Fix Filter AAAA: preserve AuthoritativeAnswer on synthesized NODATA response - #2140

Open
IReclaimer wants to merge 1 commit into
TechnitiumSoftware:masterfrom
IReclaimer:fix-filterAaaa-authoritative-flag
Open

Fix Filter AAAA: preserve AuthoritativeAnswer on synthesized NODATA response#2140
IReclaimer wants to merge 1 commit into
TechnitiumSoftware:masterfrom
IReclaimer:fix-filterAaaa-authoritative-flag

Conversation

@IReclaimer

Copy link
Copy Markdown

Fixes #2139

The synthesized NODATA response always hardcoded authoritativeAnswer to false, even when the original response was authoritative. This is correct when filtering a recursively-resolved/forwarded answer (AA=0 is right there anyway), but wrong when the server is authoritative for the zone being filtered. The confirmed negative answer gets downgraded to non-authoritative for no reason.

This matters beyond protocol correctness: a resolver forwarding to this server (e.g. Unbound with a forward-zone) treats a non-authoritative NODATA as inconclusive and falls back to real recursive resolution instead of trusting it, silently defeating the filter for anyone running this behind a forwarding resolver for their own authoritative zones.

RecursionDesired/RecursionAvailable a few arguments later were already being carried over correctly from the original response; this just extends the same treatment to AuthoritativeAnswer. See #2139 for full reproduction steps.

…esponse

The synthesized NODATA response always hardcoded authoritativeAnswer to false, even when the original response was authoritative. This is correct when filtering a recursively-resolved/forwarded answer (AA=0 is right there anyway), but wrong when the server is authoritative for the zone being filtered. The confirmed negative answer gets downgraded to non-authoritative for no reason.

This matters beyond protocol correctness: a resolver forwarding to this server (e.g. Unbound with a forward-zone) treats a non-authoritative NODATA as inconclusive and falls back to real recursive resolution instead of trusting it, silently defeating the filter for anyone running this behind a forwarding resolver for their own authoritative zones.

RecursionDesired/RecursionAvailable a few arguments later were already being carried over correctly from the original response; this just extends the same treatment to AuthoritativeAnswer.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Filter AAAA app always sets AA=0 on its synthesized NODATA response, even when the original response was authoritative

1 participant