Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider a trailing dot when resolve DNS with search domains #5963

Merged
merged 9 commits into from
Nov 8, 2024

Conversation

ikhoon
Copy link
Contributor

@ikhoon ikhoon commented Oct 30, 2024

Motivation:

There was a report from LY internally where DNS resolver warned for NXDomain unexpectedly.

java.util.concurrent.CompletionException: java.lang.IllegalArgumentException: Empty label is not a legal name
	at java.base/java.util.concurrent.CompletableFuture.encodeThrowable(CompletableFuture.java:315)
        ...
	at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver.resolve0(SearchDomainDnsResolver.java:99)
	at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver.resolve(SearchDomainDnsResolver.java:88)
	at com.linecorp.armeria.internal.client.dns.HostsFileDnsResolver.resolve(HostsFileDnsResolver.java:130)
	at com.linecorp.armeria.internal.client.dns.DefaultDnsResolver.resolveOne(DefaultDnsResolver.java:89)
	at com.linecorp.armeria.internal.client.dns.DefaultDnsResolver.resolve(DefaultDnsResolver.java:81)
	at com.linecorp.armeria.client.endpoint.dns.DnsEndpointGroup.sendQueries(DnsEndpointGroup.java:155)
	at com.linecorp.armeria.client.endpoint.dns.DnsEndpointGroup.lambda$sendQueries$3(DnsEndpointGroup.java:173)
       ...
Caused by: java.lang.IllegalArgumentException: Empty label is not a legal name
  at java.base/java.net.IDN.toASCIIInternal(IDN.java:284)
  at java.base/java.net.IDN.toASCII(IDN.java:123)
  at java.base/java.net.IDN.toASCII(IDN.java:152)
  at com.linecorp.armeria.internal.client.dns.DnsQuestionWithoutTrailingDot.<init>(DnsQuestionWithoutTrailingDot.java:53)
  at com.linecorp.armeria.internal.client.dns.DnsQuestionWithoutTrailingDot.of(DnsQuestionWithoutTrailingDot.java:48)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver$SearchDomainQuestionContext.newQuestion(SearchDomainDnsResolver.java:190)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver$SearchDomainQuestionContext.nextQuestion0(SearchDomainDnsResolver.java:177)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver$SearchDomainQuestionContext.nextQuestion(SearchDomainDnsResolver.java:150)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver.lambda$resolve0$1(SearchDomainDnsResolver.java:103)
  ... 19 common frames omitted

The NX domain has a trailing dot and search domains start with a dot (.).
As a result, example.com..search.domain was made and rejected by java.net.IDN

Modifications:

  • Remove a leading dot from the normalized search domains.
  • Infix a dot when a hostname does not have a trailing dot.

Result:

DNS resolver now correctly adds search domains for hostnames with trailing dots.

Motivation:

There was a report from LY internally where DNS resolver warns for `NXDomain`.
```
java.util.concurrent.CompletionException: java.lang.IllegalArgumentException: Empty label is not a legal name
	at java.base/java.util.concurrent.CompletableFuture.encodeThrowable(CompletableFuture.java:315)
        ...
	at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver.resolve0(SearchDomainDnsResolver.java:99)
	at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver.resolve(SearchDomainDnsResolver.java:88)
	at com.linecorp.armeria.internal.client.dns.HostsFileDnsResolver.resolve(HostsFileDnsResolver.java:130)
	at com.linecorp.armeria.internal.client.dns.DefaultDnsResolver.resolveOne(DefaultDnsResolver.java:89)
	at com.linecorp.armeria.internal.client.dns.DefaultDnsResolver.resolve(DefaultDnsResolver.java:81)
	at com.linecorp.armeria.client.endpoint.dns.DnsEndpointGroup.sendQueries(DnsEndpointGroup.java:155)
	at com.linecorp.armeria.client.endpoint.dns.DnsEndpointGroup.lambda$sendQueries$3(DnsEndpointGroup.java:173)
       ...
Caused by: java.lang.IllegalArgumentException: Empty label is not a legal name
  at java.base/java.net.IDN.toASCIIInternal(IDN.java:284)
  at java.base/java.net.IDN.toASCII(IDN.java:123)
  at java.base/java.net.IDN.toASCII(IDN.java:152)
  at com.linecorp.armeria.internal.client.dns.DnsQuestionWithoutTrailingDot.<init>(DnsQuestionWithoutTrailingDot.java:53)
  at com.linecorp.armeria.internal.client.dns.DnsQuestionWithoutTrailingDot.of(DnsQuestionWithoutTrailingDot.java:48)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver$SearchDomainQuestionContext.newQuestion(SearchDomainDnsResolver.java:190)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver$SearchDomainQuestionContext.nextQuestion0(SearchDomainDnsResolver.java:177)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver$SearchDomainQuestionContext.nextQuestion(SearchDomainDnsResolver.java:150)
  at com.linecorp.armeria.internal.client.dns.SearchDomainDnsResolver.lambda$resolve0$1(SearchDomainDnsResolver.java:103)
  ... 19 common frames omitted
```

The NX domain has with a trailing dot and search domains starts with
`.`. As a result, `example.com..search.domain` was made and rejected by `java.net.IDN`

Modifications:

- Remove a leading dot from the normalized search domains.
- Infix a dot when a hostname does not have a trailing dot.

Result:

DNS resolver now correctly adds search domains for hostnames with trailing dots.
@ikhoon ikhoon added the defect label Oct 30, 2024
@ikhoon ikhoon added this to the 1.31.0 milestone Oct 30, 2024
Copy link
Member

@minwoox minwoox left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 👍 👍

Copy link
Contributor

@jrhee17 jrhee17 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 👍

jrhee17 and others added 5 commits November 6, 2024 10:10
- Stop to send queries with search domains when it was resovled.
- Fix a bug where the original hostname was sent as the last query
  when the number of dots in a hostname >= `ndots`.
- Explicitly set `ResolvedAddressTypes.IPV4_ONLY` to avoid flakyness.
Copy link
Member

@minwoox minwoox left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still looks good 👍

@ikhoon ikhoon merged commit 460ea02 into line:main Nov 8, 2024
12 of 14 checks passed
@ikhoon ikhoon deleted the trailing-dot-searchdomain branch November 8, 2024 02:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants