Files
container/Sources/DNSServer/DNSServer+Handle.swift
T
Rado Kubiak | Rado x TechandGitHub 745cc1813e Fix container DNS resolution broken by AAAA/IPv6 NXDOMAIN handling (#786)
- In Alpine Linux containers (commonly used as Docker base images),
  standard DNS resolution is provided by **musl**, a lightweight C
  standard library (libc). Musl implements DNS lookups via
  `getaddrinfo()`, which queries AAAA (IPv6) records first.
- Problem: DNS did not work correctly **inside containers**. Any
  system command attempting to resolve hostnames
  (e.g., `ping dynamodb-admin`) **failed** when the DNS server
  responded NXDOMAIN for AAAA records, even if A (IPv4) records
  existed. Explicitly forcing IPv4 (`ping -4dynamodb-admin`) worked
  correctly, showing the issue is specific to musl’s IPv6-first behavior.
- Consequence: In IPv4-only environments, Alpine-based containers
  cannot resolve hostnames using standard tools or libraries.
  Applications relying on `getaddrinfo()` fail with ENOTFOUND,
  breaking networking and inter-container communication.
- Root cause:  Following RFC 8305 / RFC 6724, musl treats NXDOMAIN
  for AAAA as “hostname does not exist” and does not fallback to A
  (IPv4) records.
- Fix: The Apple Container DNS engine now behaves as follows:
  * If an **A record exists**, AAAA queries return **NOERROR with empty
    answer (NODATA)**.
  * If neither **A nor AAAA** exist, NXDOMAIN is returned.
  This ensures that Alpine-based containers in IPv4-only networks can
  correctly resolve hostnames inside containers without modifying
  container images or application code.
2025-10-30 17:03:17 -07:00

87 lines
3.2 KiB
Swift

//===----------------------------------------------------------------------===//
// Copyright © 2025 Apple Inc. and the container project authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// https://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//===----------------------------------------------------------------------===//
import Foundation
import NIOCore
import NIOPosix
extension DNSServer {
/// Handles the DNS request.
/// - Parameters:
/// - outbound: The NIOAsyncChannelOutboundWriter for which to respond.
/// - packet: The request packet.
func handle(
outbound: NIOAsyncChannelOutboundWriter<AddressedEnvelope<ByteBuffer>>,
packet: inout AddressedEnvelope<ByteBuffer>
) async throws {
let chunkSize = 512
var data = Data()
self.log?.debug("reading data")
while packet.data.readableBytes > 0 {
if let chunk = packet.data.readBytes(length: min(chunkSize, packet.data.readableBytes)) {
data.append(contentsOf: chunk)
}
}
self.log?.debug("deserializing message")
let query = try Message(deserialize: data)
self.log?.debug("processing query: \(query.questions)")
// always send response
let responseData: Data
do {
self.log?.debug("awaiting processing")
var response =
try await handler.answer(query: query)
?? Message(
id: query.id,
type: .response,
returnCode: .notImplemented,
questions: query.questions,
answers: []
)
// Only set NXDOMAIN if handler didn't explicitly set noError (NODATA response).
// This preserves NODATA responses for AAAA queries when A record exists,
// which prevents musl libc from treating empty AAAA as "domain doesn't exist".
if response.answers.isEmpty && response.returnCode != .noError {
response.returnCode = .nonExistentDomain
}
self.log?.debug("serializing response")
responseData = try response.serialize()
} catch {
self.log?.error("error processing message from \(query): \(error)")
let response = Message(
id: query.id,
type: .response,
returnCode: .notImplemented,
questions: query.questions,
answers: []
)
responseData = try response.serialize()
}
self.log?.debug("sending response for \(query.id)")
let rData = ByteBuffer(bytes: responseData)
try? await outbound.write(AddressedEnvelope(remoteAddress: packet.remoteAddress, data: rData))
self.log?.debug("processing done")
}
}