Skip to content

Enable Firefox plugin only when local DOH is enabled - #2954

Closed
lifenjoiner wants to merge 1 commit into
DNSCrypt:masterfrom
lifenjoiner:plugin
Closed

lifenjoiner wants to merge 1 commit into
DNSCrypt:masterfrom
lifenjoiner:plugin

Conversation

@lifenjoiner

Copy link
Copy Markdown
Member

No description provided.

@jedisct1

jedisct1 commented Sep 8, 2025

Copy link
Copy Markdown
Member

I don't use Firefox and I don't live in the US where it silently forces people to use Cloudflare, but my understanding is that the Firefox plugin is always required. Without this, Firefox will automatically use its own DoH client, especially if no DoH servers have been configured.

@welwood08

Copy link
Copy Markdown
Contributor

Correct, the purpose of the Firefox plugin is to present a canary domain for Firefox to detect that signals it to disable DoH. This plugin is not technically necessary when Firefox is using local DoH (because the user is expected to manually configure Firefox's DoH settings to point to dnscrypt-proxy) but very necessary when not using local DoH (because Firefox may automatically bypass dnscrypt-proxy using external DoH servers). Perhaps there needs to be more description/comments to explain this in the code in case that link in the comment at the top of the Firefox plugin breaks.

@jedisct1 jedisct1 closed this in 064d7ac Sep 8, 2025
@lifenjoiner

Copy link
Copy Markdown
Member Author

Oh~ OK! I don't use DOH in Firefox either. This is really weird. Forcibly interrupting Firefox using DOH is a bit weird too.

I was wondering if user controlled rules work and just tested:

  1. Use blocking rules. It should work, if users don't set blocked_query_response to IPs.
  2. Use cloaking rules like use-application-dns.net doesnotexist.com, but failed. It requires there must be no error. The rule is ignored. Is it right?

BTW:

foundIPs, err := net.LookupIP(target)

This can lead user queries to escape the encryption channels and can be improved, especially on a router. If anyone doesn't dive in, I'll have a try.

@lifenjoiner

Copy link
Copy Markdown
Member Author

Append:

Note: The canary domain only applies to users who have DoH enabled as the default option. It does not apply for users who have made the choice to turn on DoH by themselves.

https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet

@lifenjoiner
lifenjoiner deleted the plugin branch September 10, 2025 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants