Skip to content

Harden DNS proxy lifecycles and add outbound interface binding - #214

Open
aarond10 wants to merge 9 commits into
masterfrom
review/dns-proxy-hardening
Open

aarond10 wants to merge 9 commits into
masterfrom
review/dns-proxy-hardening

Conversation

@aarond10

@aarond10 aarond10 commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Summary

  • Fix TCP framing, bound in-flight requests, and queue TCP responses without blocking the event loop.
  • Preserve connection identity for asynchronous replies and drain pending TCP replies during graceful shutdown.
  • Correct resolver address-change detection and retain resolve lists through HTTPS client resets.
  • Allocate curl socket watchers on demand and fix primary-group handling when dropping privileges.
  • Add Linux outbound interface binding for HTTPS and bootstrap DNS, with startup validation and explicit flag compatibility checks.
  • Add build-only, self-contained regression tests and wire Linux interface-binding validation into CI. No new runtime library dependencies.

Validation

  • All seven unit suites pass locally on macOS in normal and UBSan builds.
  • git diff --check passes.
  • Linux GCC/Clang and privileged kernel-binding validation await GitHub Actions.
  • OpenWrt end-to-end execution has not been validated.

Review

This draft preserves the nine-commit stack for review. Please review correctness, event-loop and memory ownership, embedded resource limits, and interface-binding ergonomics before merging.

@aarond10
aarond10 marked this pull request as ready for review October 5, 2026 21:27
@aarond10

aarond10 commented Oct 5, 2026

Copy link
Copy Markdown
Owner Author

@baranyaib90, the bulk of these are AI generated. I've reviewed them and they look reasonable and I'm very happy with the better test coverage we have here now. Do you have any thoughts before a squash and merge?

@baranyaib90

Copy link
Copy Markdown
Contributor

Hi @aarond10, I'm kinda afraid already of the review. Last time there were plenty bugs in the pack.
Please give me a few weeks to check, before you merge. Thanks.

@aarond10

aarond10 commented Oct 6, 2026 via email

Copy link
Copy Markdown
Owner Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants