Executed test plan on Noble. Step 1 now shows "SECURE" instead of "TRUNCATED"
Reading package lists... Done Building dependency tree... Done Reading state information... Done The following additional packages will be installed: dns-root-data The following NEW packages will be installed: dns-root-data dnsmasq dnsmasq-base 0 upgraded, 3 newly installed, 0 to remove and 0 not upgraded. Need to get 400 kB of archives. After this operation, 955 kB of additional disk space will be used. Get:1 http://archive.ubuntu.com/ubuntu noble-updates/main amd64 dnsmasq-base amd64 2.90-2ubuntu0.4 [376 kB] Get:2 http://archive.ubuntu.com/ubuntu noble-updates/universe amd64 dnsmasq all 2.90-2ubuntu0.4 [17.9 kB] Get:3 http://archive.ubuntu.com/ubuntu noble-updates/main amd64 dns-root-data all 2024071801~ubuntu0.24.04.1 [5918 B] Fetched 400 kB in 0s (4779 kB/s) Selecting previously unselected package dnsmasq-base. (Reading database ... 37575 files and directories currently installed.) Preparing to unpack .../dnsmasq-base_2.90-2ubuntu0.4_amd64.deb ... Unpacking dnsmasq-base (2.90-2ubuntu0.4) ... Selecting previously unselected package dnsmasq. Preparing to unpack .../dnsmasq_2.90-2ubuntu0.4_all.deb ... Unpacking dnsmasq (2.90-2ubuntu0.4) ... Selecting previously unselected package dns-root-data. Preparing to unpack .../dns-root-data_2024071801~ubuntu0.24.04.1_all.deb ... Unpacking dns-root-data (2024071801~ubuntu0.24.04.1) ... Setting up dnsmasq-base (2.90-2ubuntu0.4) ... Setting up dns-root-data (2024071801~ubuntu0.24.04.1) ... Setting up dnsmasq (2.90-2ubuntu0.4) ... Created symlink /etc/systemd/system/multi-user.target.wants/dnsmasq.service → /usr/lib/systemd/system/dnsmasq.service. Could not execute systemctl: at /usr/bin/deb-systemd-invoke line 148. Processing triggers for man-db (2.12.0-4build2) ... Processing triggers for dbus (1.14.10-4ubuntu4.1) ... Scanning processes... No services need to be restarted. No containers need to be restarted. No user sessions are running outdated binaries. No VM guests are running outdated hypervisor (qemu) binaries on this host. root@dnsmasq-noble:~# bash test.sh Aug 18 20:44:34 dnsmasq[3595]: started, version 2.90 cachesize 150 Aug 18 20:44:34 dnsmasq[3595]: compile time options: IPv6 GNU-getopt DBus no-UBus i18n IDN2 DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth cryptohash DNSSEC loop-detect inotify dumpfile Aug 18 20:44:34 dnsmasq[3595]: DNSSEC validation enabled Aug 18 20:44:34 dnsmasq[3595]: configured with trust anchor for <root> keytag 20326 Aug 18 20:44:34 dnsmasq[3595]: using nameserver 8.8.8.8#53 Aug 18 20:44:34 dnsmasq[3595]: read /etc/hosts - 8 names 1. Without TCP retry (+ignore): DNSSEC validation FAILS Aug 18 20:44:36 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1 Aug 18 20:44:36 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] . to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: reply . is truncated[DNSKEY] Aug 18 20:44:36 dnsmasq[3595]: validation result is TRUNCATED Aug 18 20:44:36 dnsmasq[3595]: reply is truncated ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34991 Aug 18 20:44:36 dnsmasq[3595]: validation result is TRUNCATED 2. With TCP retry: validation succeeds Aug 18 20:44:36 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1 Aug 18 20:44:36 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] . to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: reply . is truncated[DNSKEY] Aug 18 20:44:36 dnsmasq[3595]: validation result is TRUNCATED Aug 18 20:44:36 dnsmasq[3595]: reply is truncated Aug 18 20:44:36 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1 Aug 18 20:44:36 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] . to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: reply . is DNSKEY keytag 20326, algo 8 Aug 18 20:44:36 dnsmasq[3595]: reply . is DNSKEY keytag 38696, algo 8 Aug 18 20:44:36 dnsmasq[3595]: reply . is DNSKEY keytag 57780, algo 8 Aug 18 20:44:36 dnsmasq[3595]: reply com is DS for keytag 19718, algo 13, digest 2 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] cloudflare.com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: reply com is DNSKEY keytag 19718, algo 13 Aug 18 20:44:36 dnsmasq[3595]: reply com is DNSKEY keytag 41446, algo 13 Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is DS for keytag 2371, algo 13, digest 2 Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] cloudflare.com to 8.8.8.8 Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is DNSKEY keytag 34505, algo 13 Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is DNSKEY keytag 2371, algo 13 Aug 18 20:44:36 dnsmasq[3595]: validation result is SECURE Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is 104.16.133.229 Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is 104.16.132.229 ;; Truncated, retrying in TCP mode. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 8567 Aug 18 20:44:36 dnsmasq[3595]: validation result is SECURE 3. From cache: returns instantly (0ms), background refresh has no TCP retry Aug 18 20:44:39 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1 Aug 18 20:44:39 dnsmasq[3595]: cached-stale cloudflare.com is 104.16.133.229 Aug 18 20:44:39 dnsmasq[3595]: cached-stale cloudflare.com is 104.16.132.229 Aug 18 20:44:39 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8 ; EDE: 3 (Stale Answer) ;; Query time: 0 msec Aug 18 20:44:39 dnsmasq[3595]: cached-stale cloudflare.com is 104.16.132.229 Aug 18 20:44:39 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8 full dnsmasq log in /tmp/tmp.U1kg02xfe1 Aug 18 20:44:39 dnsmasq[3595]: exiting on receipt of SIGTERM root@dnsmasq-noble:~# apt install -yt noble-proposed dnsmasq dnsmasq-base Reading package lists... Done Building dependency tree... Done Reading state information... Done The following packages will be upgraded: dnsmasq dnsmasq-base 2 upgraded, 0 newly installed, 0 to remove and 24 not upgraded. Need to get 399 kB of archives. After this operation, 9216 B of additional disk space will be used. Get:1 http://archive.ubuntu.com/ubuntu noble-proposed/main amd64 dnsmasq-base amd64 2.91-0ubuntu0.24.04.1 [381 kB] Get:2 http://archive.ubuntu.com/ubuntu noble-proposed/universe amd64 dnsmasq all 2.91-0ubuntu0.24.04.1 [17.9 kB] Fetched 399 kB in 3s (152 kB/s) (Reading database ... 37624 files and directories currently installed.) Preparing to unpack .../dnsmasq-base_2.91-0ubuntu0.24.04.1_amd64.deb ... Unpacking dnsmasq-base (2.91-0ubuntu0.24.04.1) over (2.90-2ubuntu0.4) ... Preparing to unpack .../dnsmasq_2.91-0ubuntu0.24.04.1_all.deb ... Unpacking dnsmasq (2.91-0ubuntu0.24.04.1) over (2.90-2ubuntu0.4) ... Setting up dnsmasq-base (2.91-0ubuntu0.24.04.1) ... Setting up dnsmasq (2.91-0ubuntu0.24.04.1) ... Could not execute systemctl: at /usr/bin/deb-systemd-invoke line 148. Processing triggers for man-db (2.12.0-4build2) ... Processing triggers for dbus (1.14.10-4ubuntu4.1) ... Scanning processes... No services need to be restarted. No containers need to be restarted. No user sessions are running outdated binaries. No VM guests are running outdated hypervisor (qemu) binaries on this host. root@dnsmasq-noble:~# bash test.sh Aug 18 20:45:06 dnsmasq[3908]: started, version 2.91 cachesize 150 Aug 18 20:45:06 dnsmasq[3908]: compile time options: IPv6 GNU-getopt DBus no-UBus i18n IDN2 DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC loop-detect inotify dumpfile Aug 18 20:45:06 dnsmasq[3908]: DNSSEC validation enabled Aug 18 20:45:06 dnsmasq[3908]: configured with trust anchor for <root> keytag 20326 Aug 18 20:45:06 dnsmasq[3908]: using nameserver 8.8.8.8#53 Aug 18 20:45:06 dnsmasq[3908]: read /etc/hosts - 8 names 1. Without TCP retry (+ignore): DNSSEC validation FAILS Aug 18 20:45:08 dnsmasq[3908]: query[A] cloudflare.com from 127.0.0.1 Aug 18 20:45:08 dnsmasq[3908]: forwarded cloudflare.com to 8.8.8.8 Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DS] com to 8.8.8.8 Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] . to 8.8.8.8 Aug 18 20:45:08 dnsmasq[3908]: reply . is truncated Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] . to 8.8.8.8 Aug 18 20:45:08 dnsmasq[3908]: reply . is DNSKEY keytag 38696, algo 8 Aug 18 20:45:08 dnsmasq[3908]: reply . is DNSKEY keytag 57780, algo 8 Aug 18 20:45:08 dnsmasq[3908]: reply . is DNSKEY keytag 20326, algo 8 Aug 18 20:45:08 dnsmasq[3908]: reply com is DS for keytag 19718, algo 13, digest 2 Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DS] cloudflare.com to 8.8.8.8 Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] com to 8.8.8.8 Aug 18 20:45:08 dnsmasq[3908]: reply com is DNSKEY keytag 19718, algo 13 Aug 18 20:45:08 dnsmasq[3908]: reply com is DNSKEY keytag 41446, algo 13 Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is DS for keytag 2371, algo 13, digest 2 Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] cloudflare.com to 8.8.8.8 Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is DNSKEY keytag 2371, algo 13 Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is DNSKEY keytag 34505, algo 13 Aug 18 20:45:08 dnsmasq[3908]: validation result is SECURE Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is 104.16.133.229 Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is 104.16.132.229 ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 9310 Aug 18 20:45:08 dnsmasq[3908]: validation result is SECURE 2. With TCP retry: validation succeeds Aug 18 20:45:08 dnsmasq[3908]: query[A] cloudflare.com from 127.0.0.1 Aug 18 20:45:08 dnsmasq[3908]: cached cloudflare.com is 104.16.133.229 Aug 18 20:45:08 dnsmasq[3908]: cached cloudflare.com is 104.16.132.229 ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46986 Aug 18 20:45:08 dnsmasq[3908]: validation result is SECURE 3. From cache: returns instantly (0ms), background refresh has no TCP retry Aug 18 20:45:11 dnsmasq[3908]: query[A] cloudflare.com from 127.0.0.1 Aug 18 20:45:11 dnsmasq[3908]: cached-stale cloudflare.com is 104.16.132.229 Aug 18 20:45:11 dnsmasq[3908]: cached-stale cloudflare.com is 104.16.133.229 Aug 18 20:45:11 dnsmasq[3908]: forwarded cloudflare.com to 8.8.8.8 ; EDE: 3 (Stale Answer) ;; Query time: 0 msec Aug 18 20:45:11 dnsmasq[3908]: cached-stale cloudflare.com is 104.16.133.229 Aug 18 20:45:11 dnsmasq[3908]: forwarded cloudflare.com to 8.8.8.8 full dnsmasq log in /tmp/tmp.AkQAJKwHfl Aug 18 20:45:11 dnsmasq[3908]: exiting on receipt of SIGTERM ** Tags removed: verification-needed-noble ** Tags added: verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2138412 Title: DNSSEC validation with stale cache enabled does not properly retry truncated response To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/2138412/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
