Executed test plan on Noble. Step 1 now shows "SECURE" instead of
"TRUNCATED"

Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
The following additional packages will be installed:
  dns-root-data
The following NEW packages will be installed:
  dns-root-data dnsmasq dnsmasq-base
0 upgraded, 3 newly installed, 0 to remove and 0 not upgraded.
Need to get 400 kB of archives.
After this operation, 955 kB of additional disk space will be used.
Get:1 http://archive.ubuntu.com/ubuntu noble-updates/main amd64 dnsmasq-base 
amd64 2.90-2ubuntu0.4 [376 kB]
Get:2 http://archive.ubuntu.com/ubuntu noble-updates/universe amd64 dnsmasq all 
2.90-2ubuntu0.4 [17.9 kB]
Get:3 http://archive.ubuntu.com/ubuntu noble-updates/main amd64 dns-root-data 
all 2024071801~ubuntu0.24.04.1 [5918 B]
Fetched 400 kB in 0s (4779 kB/s)
Selecting previously unselected package dnsmasq-base.
(Reading database ... 37575 files and directories currently installed.)
Preparing to unpack .../dnsmasq-base_2.90-2ubuntu0.4_amd64.deb ...
Unpacking dnsmasq-base (2.90-2ubuntu0.4) ...
Selecting previously unselected package dnsmasq.
Preparing to unpack .../dnsmasq_2.90-2ubuntu0.4_all.deb ...
Unpacking dnsmasq (2.90-2ubuntu0.4) ...
Selecting previously unselected package dns-root-data.
Preparing to unpack .../dns-root-data_2024071801~ubuntu0.24.04.1_all.deb ...
Unpacking dns-root-data (2024071801~ubuntu0.24.04.1) ...
Setting up dnsmasq-base (2.90-2ubuntu0.4) ...
Setting up dns-root-data (2024071801~ubuntu0.24.04.1) ...
Setting up dnsmasq (2.90-2ubuntu0.4) ...
Created symlink /etc/systemd/system/multi-user.target.wants/dnsmasq.service → 
/usr/lib/systemd/system/dnsmasq.service.
Could not execute systemctl:  at /usr/bin/deb-systemd-invoke line 148.
Processing triggers for man-db (2.12.0-4build2) ...
Processing triggers for dbus (1.14.10-4ubuntu4.1) ...
Scanning processes...

No services need to be restarted.

No containers need to be restarted.

No user sessions are running outdated binaries.

No VM guests are running outdated hypervisor (qemu) binaries on this host.
root@dnsmasq-noble:~# bash test.sh
Aug 18 20:44:34 dnsmasq[3595]: started, version 2.90 cachesize 150
Aug 18 20:44:34 dnsmasq[3595]: compile time options: IPv6 GNU-getopt DBus 
no-UBus i18n IDN2 DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth 
cryptohash DNSSEC loop-detect inotify dumpfile
Aug 18 20:44:34 dnsmasq[3595]: DNSSEC validation enabled
Aug 18 20:44:34 dnsmasq[3595]: configured with trust anchor for <root> keytag 
20326
Aug 18 20:44:34 dnsmasq[3595]: using nameserver 8.8.8.8#53
Aug 18 20:44:34 dnsmasq[3595]: read /etc/hosts - 8 names

1. Without TCP retry (+ignore): DNSSEC validation FAILS
Aug 18 20:44:36 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1
Aug 18 20:44:36 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] . to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: reply . is truncated[DNSKEY]
Aug 18 20:44:36 dnsmasq[3595]: validation result is TRUNCATED
Aug 18 20:44:36 dnsmasq[3595]: reply is truncated
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34991
Aug 18 20:44:36 dnsmasq[3595]: validation result is TRUNCATED

2. With TCP retry: validation succeeds
Aug 18 20:44:36 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1
Aug 18 20:44:36 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] . to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: reply . is truncated[DNSKEY]
Aug 18 20:44:36 dnsmasq[3595]: validation result is TRUNCATED
Aug 18 20:44:36 dnsmasq[3595]: reply is truncated
Aug 18 20:44:36 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1
Aug 18 20:44:36 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] . to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: reply . is DNSKEY keytag 20326, algo 8
Aug 18 20:44:36 dnsmasq[3595]: reply . is DNSKEY keytag 38696, algo 8
Aug 18 20:44:36 dnsmasq[3595]: reply . is DNSKEY keytag 57780, algo 8
Aug 18 20:44:36 dnsmasq[3595]: reply com is DS for keytag 19718, algo 13, 
digest 2
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DS] cloudflare.com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: reply com is DNSKEY keytag 19718, algo 13
Aug 18 20:44:36 dnsmasq[3595]: reply com is DNSKEY keytag 41446, algo 13
Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is DS for keytag 2371, algo 
13, digest 2
Aug 18 20:44:36 dnsmasq[3595]: dnssec-query[DNSKEY] cloudflare.com to 8.8.8.8
Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is DNSKEY keytag 34505, 
algo 13
Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is DNSKEY keytag 2371, algo 
13
Aug 18 20:44:36 dnsmasq[3595]: validation result is SECURE
Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is 104.16.133.229
Aug 18 20:44:36 dnsmasq[3595]: reply cloudflare.com is 104.16.132.229
;; Truncated, retrying in TCP mode.
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 8567
Aug 18 20:44:36 dnsmasq[3595]: validation result is SECURE

3. From cache: returns instantly (0ms), background refresh has no TCP retry
Aug 18 20:44:39 dnsmasq[3595]: query[A] cloudflare.com from 127.0.0.1
Aug 18 20:44:39 dnsmasq[3595]: cached-stale cloudflare.com is 104.16.133.229
Aug 18 20:44:39 dnsmasq[3595]: cached-stale cloudflare.com is 104.16.132.229
Aug 18 20:44:39 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8
; EDE: 3 (Stale Answer)
;; Query time: 0 msec
Aug 18 20:44:39 dnsmasq[3595]: cached-stale cloudflare.com is 104.16.132.229
Aug 18 20:44:39 dnsmasq[3595]: forwarded cloudflare.com to 8.8.8.8
full dnsmasq log in /tmp/tmp.U1kg02xfe1
Aug 18 20:44:39 dnsmasq[3595]: exiting on receipt of SIGTERM
root@dnsmasq-noble:~# apt install -yt noble-proposed dnsmasq dnsmasq-base
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
The following packages will be upgraded:
  dnsmasq dnsmasq-base
2 upgraded, 0 newly installed, 0 to remove and 24 not upgraded.
Need to get 399 kB of archives.
After this operation, 9216 B of additional disk space will be used.
Get:1 http://archive.ubuntu.com/ubuntu noble-proposed/main amd64 dnsmasq-base 
amd64 2.91-0ubuntu0.24.04.1 [381 kB]
Get:2 http://archive.ubuntu.com/ubuntu noble-proposed/universe amd64 dnsmasq 
all 2.91-0ubuntu0.24.04.1 [17.9 kB]
Fetched 399 kB in 3s (152 kB/s)
(Reading database ... 37624 files and directories currently installed.)
Preparing to unpack .../dnsmasq-base_2.91-0ubuntu0.24.04.1_amd64.deb ...
Unpacking dnsmasq-base (2.91-0ubuntu0.24.04.1) over (2.90-2ubuntu0.4) ...
Preparing to unpack .../dnsmasq_2.91-0ubuntu0.24.04.1_all.deb ...
Unpacking dnsmasq (2.91-0ubuntu0.24.04.1) over (2.90-2ubuntu0.4) ...
Setting up dnsmasq-base (2.91-0ubuntu0.24.04.1) ...
Setting up dnsmasq (2.91-0ubuntu0.24.04.1) ...
Could not execute systemctl:  at /usr/bin/deb-systemd-invoke line 148.
Processing triggers for man-db (2.12.0-4build2) ...
Processing triggers for dbus (1.14.10-4ubuntu4.1) ...
Scanning processes...

No services need to be restarted.

No containers need to be restarted.

No user sessions are running outdated binaries.

No VM guests are running outdated hypervisor (qemu) binaries on this host.
root@dnsmasq-noble:~# bash test.sh
Aug 18 20:45:06 dnsmasq[3908]: started, version 2.91 cachesize 150
Aug 18 20:45:06 dnsmasq[3908]: compile time options: IPv6 GNU-getopt DBus 
no-UBus i18n IDN2 DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC 
loop-detect inotify dumpfile
Aug 18 20:45:06 dnsmasq[3908]: DNSSEC validation enabled
Aug 18 20:45:06 dnsmasq[3908]: configured with trust anchor for <root> keytag 
20326
Aug 18 20:45:06 dnsmasq[3908]: using nameserver 8.8.8.8#53
Aug 18 20:45:06 dnsmasq[3908]: read /etc/hosts - 8 names

1. Without TCP retry (+ignore): DNSSEC validation FAILS
Aug 18 20:45:08 dnsmasq[3908]: query[A] cloudflare.com from 127.0.0.1
Aug 18 20:45:08 dnsmasq[3908]: forwarded cloudflare.com to 8.8.8.8
Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DS] com to 8.8.8.8
Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] . to 8.8.8.8
Aug 18 20:45:08 dnsmasq[3908]: reply . is truncated
Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] . to 8.8.8.8
Aug 18 20:45:08 dnsmasq[3908]: reply . is DNSKEY keytag 38696, algo 8
Aug 18 20:45:08 dnsmasq[3908]: reply . is DNSKEY keytag 57780, algo 8
Aug 18 20:45:08 dnsmasq[3908]: reply . is DNSKEY keytag 20326, algo 8
Aug 18 20:45:08 dnsmasq[3908]: reply com is DS for keytag 19718, algo 13, 
digest 2
Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DS] cloudflare.com to 8.8.8.8
Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] com to 8.8.8.8
Aug 18 20:45:08 dnsmasq[3908]: reply com is DNSKEY keytag 19718, algo 13
Aug 18 20:45:08 dnsmasq[3908]: reply com is DNSKEY keytag 41446, algo 13
Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is DS for keytag 2371, algo 
13, digest 2
Aug 18 20:45:08 dnsmasq[3908]: dnssec-query[DNSKEY] cloudflare.com to 8.8.8.8
Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is DNSKEY keytag 2371, algo 
13
Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is DNSKEY keytag 34505, 
algo 13
Aug 18 20:45:08 dnsmasq[3908]: validation result is SECURE
Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is 104.16.133.229
Aug 18 20:45:08 dnsmasq[3908]: reply cloudflare.com is 104.16.132.229
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 9310
Aug 18 20:45:08 dnsmasq[3908]: validation result is SECURE

2. With TCP retry: validation succeeds
Aug 18 20:45:08 dnsmasq[3908]: query[A] cloudflare.com from 127.0.0.1
Aug 18 20:45:08 dnsmasq[3908]: cached cloudflare.com is 104.16.133.229
Aug 18 20:45:08 dnsmasq[3908]: cached cloudflare.com is 104.16.132.229
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46986
Aug 18 20:45:08 dnsmasq[3908]: validation result is SECURE

3. From cache: returns instantly (0ms), background refresh has no TCP retry
Aug 18 20:45:11 dnsmasq[3908]: query[A] cloudflare.com from 127.0.0.1
Aug 18 20:45:11 dnsmasq[3908]: cached-stale cloudflare.com is 104.16.132.229
Aug 18 20:45:11 dnsmasq[3908]: cached-stale cloudflare.com is 104.16.133.229
Aug 18 20:45:11 dnsmasq[3908]: forwarded cloudflare.com to 8.8.8.8
; EDE: 3 (Stale Answer)
;; Query time: 0 msec
Aug 18 20:45:11 dnsmasq[3908]: cached-stale cloudflare.com is 104.16.133.229
Aug 18 20:45:11 dnsmasq[3908]: forwarded cloudflare.com to 8.8.8.8
full dnsmasq log in /tmp/tmp.AkQAJKwHfl
Aug 18 20:45:11 dnsmasq[3908]: exiting on receipt of SIGTERM


** Tags removed: verification-needed-noble
** Tags added: verification-done-noble

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2138412

Title:
  DNSSEC validation with stale cache enabled does not properly retry
  truncated response

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/dnsmasq/+bug/2138412/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to