惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
IT之家
IT之家
D
Docker
博客园 - 叶小钗
A
About on SuperTechFans
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
Recorded Future
Recorded Future
Stack Overflow Blog
Stack Overflow Blog
腾讯CDC
V
V2EX
S
SegmentFault 最新的问题
量子位
P
Proofpoint News Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
Latest news
Latest news
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
有赞技术团队
有赞技术团队
The GitHub Blog
The GitHub Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
DataBreaches.Net
G
GRAHAM CLULEY
P
Proofpoint News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Microsoft Security Blog
Microsoft Security Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Y
Y Combinator Blog
小众软件
小众软件
NISL@THU
NISL@THU
L
Lohrmann on Cybersecurity
aimingoo的专栏
aimingoo的专栏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
I
Intezer
Last Week in AI
Last Week in AI
T
Threatpost
人人都是产品经理
人人都是产品经理
U
Unit 42
Security Latest
Security Latest
AWS News Blog
AWS News Blog
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
罗磊的独立博客
GbyAI
GbyAI
P
Palo Alto Networks Blog
G
Google Developers Blog
MyScale Blog
MyScale Blog
L
LangChain Blog

dnsmasq-discuss

[Dnsmasq-discuss] Announce: dnsmasq-2.92rc2 Re: [Dnsmasq-discuss] [PATCH] Fix arguments order for chaos subdomain check Re: [Dnsmasq-discuss] patch: block-file/allow-file - for review/feedback Re: [Dnsmasq-discuss] patch: block-file/allow-file - for review/feedback Re: [Dnsmasq-discuss] patch: block-file/allow-file - for review/feedback Re: [Dnsmasq-discuss] patch: block-file/allow-file - for review/feedback [Dnsmasq-discuss] patch: block-file/allow-file - for review/feedback Re: [Dnsmasq-discuss] server= with interface parameter changes behavior over time [Dnsmasq-discuss] NFTsets and hosts-files [Dnsmasq-discuss] [PATCH] Allow expired RRSIGs when stale caching is enabled [Dnsmasq-discuss] [PATCH] Fix local host records being overridden by upstream NXDOMAIN [Dnsmasq-discuss] [PATCH] Fix arguments order for chaos subdomain check Re: [Dnsmasq-discuss] Malformed RRSIG Can Crash dnsmasq [Dnsmasq-discuss] Malformed NSEC/NSEC3 Can Hang dnsmasq [Dnsmasq-discuss] Malformed RRSIG Can Crash dnsmasq [Dnsmasq-discuss] Security - IMPORTANT Re: [Dnsmasq-discuss] Issue with circuit-id matching on dhcp requests Re: [Dnsmasq-discuss] Issue with circuit-id matching on dhcp requests Re: [Dnsmasq-discuss] Issue with circuit-id matching on dhcp requests [Dnsmasq-discuss] Issue with circuit-id matching on dhcp requests Re: [Dnsmasq-discuss] [PATCH] bpf.c: fix memory leak in arp_enumerate() on BSD Re: [Dnsmasq-discuss] [PATCH] bpf.c: fix memory leak in arp_enumerate() on BSD Re: [Dnsmasq-discuss] dnssec problem here and now Re: [Dnsmasq-discuss] dnssec problem here and now [Dnsmasq-discuss] dnssec problem here and now Re: [Dnsmasq-discuss] server= with interface parameter changes behavior over time Re: [Dnsmasq-discuss] [PATCH] bpf.c: fix memory leak in arp_enumerate() on BSD Re: [Dnsmasq-discuss] [PATCH] bpf.c: fix memory leak in arp_enumerate() on BSD Re: [Dnsmasq-discuss] [PATCH] Preserve existing log file permissions when adding group-write bit. [Dnsmasq-discuss] server= with interface parameter changes behavior over time [Dnsmasq-discuss] [PATCH] bpf.c: fix memory leak in arp_enumerate() on BSD Re: [Dnsmasq-discuss] [PATCH] Preserve existing log file permissions when adding group-write bit. Re: [Dnsmasq-discuss] [BUG] SIGSEGV when parsing invalid "--interface-name" or "--dynamic-host" options Re: [Dnsmasq-discuss] Suggestion to increase default for max-tcp-connections [Dnsmasq-discuss] server priority clarification after e86d53c [Dnsmasq-discuss] [BUG] SIGSEGV when parsing invalid "--interface-name" or "--dynamic-host" options [Dnsmasq-discuss] Suggestion to increase default for max-tcp-connections Re: [Dnsmasq-discuss] [PATCH] Preserve existing log file permissions when adding group-write bit. [Dnsmasq-discuss] [Bug] Heap buffer overflow in cache_recv_insert() due to pipe de-synchronization Re: [Dnsmasq-discuss] Regression/Feature Request for 2.92 Re: [Dnsmasq-discuss] [PATCH] DHCPv6 network range is not checked well with dhcp-sequential-ip [Dnsmasq-discuss] [Bug] Buffer underflow in hostname_issubdomain() [Dnsmasq-discuss] [PATCH] Don't penalize conditional forwarders for REFUSED responses [Dnsmasq-discuss] BUG:Heap buffer overflow in src/forward.c due to incorrect pointer arithmetic (CWE-122) Re: [Dnsmasq-discuss] Regression/Feature Request for 2.92 Re: [Dnsmasq-discuss] Regression/Feature Request for 2.92 Re: [Dnsmasq-discuss] Regression/Feature Request for 2.92 Re: [Dnsmasq-discuss] Potential privacy issue: filter-rr inefficiency Re: [Dnsmasq-discuss] TCP optimization regressions Re: [Dnsmasq-discuss] Bug: Null pointer dereference in domain-match.c at line 82 (dnsmasq 2.92test21-1-gee09f06) [Dnsmasq-discuss] [PATCH] ubus: add lease management methods [Dnsmasq-discuss] Regression/Feature Request for 2.92 [Dnsmasq-discuss] cotillon por mayor [Dnsmasq-discuss] Por Qué el Alquiler de Plataformas Elevadoras es la Clave del Éxito para Tu Empresa Re: [Dnsmasq-discuss] [PATCH] dnsmasq: failed to create inotify for /etc/resolv.conf: No space left on device [Dnsmasq-discuss] Bug: Null pointer dereference in domain-match.c at line 82 (dnsmasq 2.92test21-1-gee09f06) [Dnsmasq-discuss] TCP optimization regressions Re: [Dnsmasq-discuss] [PATCH] dnsmasq: failed to create inotify for /etc/resolv.conf: No space left on device Re: [Dnsmasq-discuss] dnsmasq 2.92 build-error against Nettle 4.0 Re: [Dnsmasq-discuss] dnsmasq 2.92 build-error against Nettle 4.0 Re: [Dnsmasq-discuss] dnsmasq 2.92 build-error against Nettle 4.0 [Dnsmasq-discuss] dnsmasq 2.92 build-error against Nettle 4.0 [Dnsmasq-discuss] Potential privacy issue: filter-rr inefficiency Re: [Dnsmasq-discuss] Bug with NS records when using dnsmasq as authoritative nameserver without specific auth-interface Re: [Dnsmasq-discuss] Bug with NS records when using dnsmasq as authoritative nameserver without specific auth-interface Re: [Dnsmasq-discuss] segfault with an empty OPTION_SNAME [Dnsmasq-discuss] Bug with NS records when using dnsmasq as authoritative nameserver without specific auth-interface Re: [Dnsmasq-discuss] segfault with an empty OPTION_SNAME [Dnsmasq-discuss] segfault with an empty OPTION_SNAME Re: [Dnsmasq-discuss] Shut down caused by device request address. Re: [Dnsmasq-discuss] Shut down caused by device request address. [Dnsmasq-discuss] Shut down caused by device request address. [Dnsmasq-discuss] [PATCH] dnsmasq: failed to create inotify for /etc/resolv.conf: No space left on device Re: [Dnsmasq-discuss] dnsmasq with high availability and dynamic range [Dnsmasq-discuss] dnsmasq with high availability and dynamic range [Dnsmasq-discuss] PATCH] PXE boot server (PXEBS) responses broken in 2.92 — missing else in dhcp.c [Dnsmasq-discuss] PATCH] PXE boot server (PXEBS) responses broken in 2.92 — missing else in dhcp.c [Dnsmasq-discuss] Potential memory leak Re: [Dnsmasq-discuss] Incorrect SERVFAIL on dnssec and rivcoed.org. domain [Dnsmasq-discuss] Announce: dnsmasq-2.92 Re: [Dnsmasq-discuss] dnsmasq does not forward requests with no default route is set [Dnsmasq-discuss] DNSSEC validation fails for wildcard subdomains [Dnsmasq-discuss] Add an option to not always add a pseudo header? Re: [Dnsmasq-discuss] Announce: 2.92.rc1, rc3 & patches overseen Re: [Dnsmasq-discuss] Portable PXE boot appliance [Dnsmasq-discuss] Portable PXE boot appliance Re: [Dnsmasq-discuss] Question about IPv6 settings [Dnsmasq-discuss] Incorrect SERVFAIL on dnssec and rivcoed.org. domain [Dnsmasq-discuss] Question about IPv6 settings Re: [Dnsmasq-discuss] iPhone 17 Pro Max DHCP not working [Dnsmasq-discuss] iPhone 17 Pro Max DHCP not working Re: [Dnsmasq-discuss] [PATCH 0/3] Announce: 2.92.rc1 [Dnsmasq-discuss] [PATCH 0/3] Announce: 2.92.rc1 [Dnsmasq-discuss] [PATCH 3/3] Fix some issues with the swedish manual page, some causing lintian warnings [Dnsmasq-discuss] [PATCH2/3] Fix typos in the english manual page [Dnsmasq-discuss] [PATCH 1/3] Remove trailing white space from dnsmasq.conf.example [Dnsmasq-discuss] Announce: 2.92.rc1 [Dnsmasq-discuss] dnsmasq rejects TCP queries originating from Kubernetes pods Re: [Dnsmasq-discuss] Git: Is first dhcp.c address_available() for/if code correct? [Dnsmasq-discuss] [PATCH dnsmasq 1/1] fix SIGSEGV in dbus.c when no dhcp-range is configured
[Dnsmasq-discuss] Don't mix local (hosts/DHCP/config) records with cached upstream data
Dominik Derigs via Dnsmasq-discuss · 2026-06-20 · via dnsmasq-discuss
Hi Simon, all,

we have run into a case where dnsmasq returns an authoritative local record
together with a cached upstream record for the same name, and additionally
forwards the query upstream even though it already has a local answer.

It happens when an upstream answer for a name is cached before a local record for that same name comes into existence, which is easy to hit with a hostsdir: adding or modifying a hosts file there triggers an inotify reload of just that
file, without flushing the rest of the cache. The previously cached upstream
record stays around (and, with --use-stale-cache, lingers as a stale entry once its TTL passes). On the next query, answer_request() walks the whole cache chain
for the name and adds both records to the reply; the expired upstream record
also sets *stale, which forwards the query to refresh it.

A restart clears the cache and the symptom disappears until the name is resolved
upstream again, which is what makes it look intermittent.

Minimal reproducer (two loopback instances, no real network):

  # upstream, authoritative for repro.test with a short TTL
  dnsmasq --port=5392 --listen-address=127.0.0.1 --bind-interfaces \
          --no-resolv --no-hosts --keep-in-foreground \
          --address=/repro.test/192.0.2.50 --local-ttl=2 &

  mkdir -p /tmp/hd
  # under test
  dnsmasq --port=5391 --listen-address=127.0.0.1 --bind-interfaces \
          --no-resolv --no-hosts --keep-in-foreground \
          --server=127.0.0.1#5392 --hostsdir=/tmp/hd \
          --use-stale-cache=3600 --log-queries=extra &

  dig +short @127.0.0.1 -p 5391 repro.test A      # prime cache -> 192.0.2.50
  echo "192.168.0.99 repro.test" > /tmp/hd/custom.list
  sleep 4                                          # let the upstream entry go stale
  dig +noall +answer @127.0.0.1 -p 5391 repro.test A

Before the patch the final answer contains both 192.168.0.99 (local) and
192.0.2.50 (stale upstream), and the log shows the query being forwarded. After
the patch only 192.168.0.99 is returned, with no forward.

The fix relies on cache_find_by_name() returning all local
(F_HOSTS/F_DHCP/F_CONFIG) records for a name ahead of any cached records: once a local record has answered, stop at the first non-local record so it is neither added to the reply nor allowed to set *stale. Multiple local records, and the
normal case of multiple cached upstream records with no local record, are
unaffected.

Patch attached.

Warm regards,

Dominik
From 4b902310c30b81e6cb0652d5c264f40cb260fb81 Mon Sep 17 00:00:00 2001
From: Dominik Derigs <[email protected]>
Date: Fri, 19 Jun 2026 20:32:41 +0200
Subject: [PATCH] Don't mix local (hosts/DHCP/config) records with cached
 upstream data

When a name has an authoritative local record (from /etc/hosts, a
hostsdir file, DHCP or a config "address") and a record for the same
name is also present in the cache from earlier upstream resolution,
answer_request() walked the entire cache chain for that name and added
both to the reply. With --use-stale-cache the expired upstream record
additionally set *stale, triggering a needless upstream refresh even
though an authoritative local answer was available.

This is reachable whenever an upstream answer is cached before the local
record exists, e.g. a hostsdir file is created or modified at run time:
the inotify reload re-reads that hosts file but does not flush the rest
of the cache. The client then receives both the local address and a
stale upstream address, and the query is forwarded. Flushing the cache
(a restart) hides it until the name is resolved upstream again.

cache_find_by_name() returns all local (F_HOSTS/F_DHCP/F_CONFIG) records
for a name ahead of any cached records. So once a local record has
answered, stop at the first non-local record: do not add it to the reply
and do not let it set *stale.
---
 src/rfc1035.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/src/rfc1035.c b/src/rfc1035.c
index 16df1b1..5534446 100644
--- a/src/rfc1035.c
+++ b/src/rfc1035.c
@@ -2028,6 +2028,12 @@ size_t answer_request(struct dns_header *header, char *limit, size_t qlen,
 		  crecp = save;
 		}
 	      
+	      /* An authoritative local record (/etc/hosts, DHCP or config) must
+		 not be mixed in a reply with cached upstream records for the same
+		 name. cache_find_by_name() returns all local records ahead of any
+		 cached records, so remember whether we started from a local one. */
+	      int local_auth = (crecp->flags & (F_HOSTS | F_DHCP | F_CONFIG)) != 0;
+
 	      /* If the client asked for DNSSEC  don't use cached data. */
 	      if ((crecp->flags & (F_HOSTS | F_DHCP | F_CONFIG)) ||
 		  (rd_bit && (!do_bit || cache_not_validated(crecp)) ))
@@ -2035,6 +2041,12 @@ size_t answer_request(struct dns_header *header, char *limit, size_t qlen,
 		  { 
 		    int stale_flag = 0;
 		    
+		    /* Once a local record has answered, stop at the first cached
+		       upstream record: don't add it to the reply and don't let it
+		       trigger a stale refresh (which would forward the query). */
+		    if (local_auth && !(crecp->flags & (F_HOSTS | F_DHCP | F_CONFIG)))
+		      break;
+
 		    if (crec_isstale(crecp, now))
 		      {
 			if (stale)
-- 
2.43.0

_______________________________________________
Dnsmasq-discuss mailing list
[email protected]
https://lists.thekelleys.org.uk/cgi-bin/mailman/listinfo/dnsmasq-discuss