network.dns.localdomains does not apply to FQDN
Categories
(Core :: Networking: DNS, defect, P2)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox127 | --- | fixed |
People
(Reporter: valentin, Assigned: twisniewski)
Details
(Whiteboard: [necko-triaged][necko-priority-next])
Attachments
(1 file)
Thomas pointed out that while https://wpt.live/fetch/metadata/trailing-dot.https.sub.any.html seems to pass in the browser, https://wpt.fyi/results/fetch/metadata/trailing-dot.https.sub.any.html?label=experimental&label=master&aligned still shows some failures.
according to james: "So we're using network.dns.localdomains to bypass the DNS. If that test is doing something not supported by that codepath then that would explain what you're seeing. The simple test here would be to just add all the domains twice, once with a trailing dot. Or have necko preprocess the domain before we call https://searchfox.org/mozilla-central/source/netwerk/dns/nsDNSService2.cpp#999 (which I think is where we end up trying to decide if we should treat the domain as local)"
I think we should update this check:
localDomain = mLocalDomains.Contains(aHostname);
to be something like
localDomain = mLocalDomains.Contains(StringEndsWith(aHostname, "."_ns) ? Substring(aHostname, ...) : aHostname);
That way both example.com and example.com. would be covered by the pref.
| Assignee | ||
Comment 1•2 years ago
|
||
| Assignee | ||
Comment 2•2 years ago
|
||
Updated•2 years ago
|
Comment 4•2 years ago
|
||
Backed out for causing xpcshell failures in test_pinning.js.
- Backout link
- Push with failures
- Failure Log
- Failure line: TEST-UNEXPECTED-TIMEOUT | security/manager/ssl/tests/unit/test_pinning.js | Test timed out
| Assignee | ||
Comment 5•2 years ago
|
||
Valentin, these are the tests which are hanging:
// Check that using a FQDN doesn't bypass pinning.
add_connection_test(
"bad.include-subdomains.pinning.example.com.",
MOZILLA_PKIX_ERROR_KEY_PINNING_FAILURE
);
// For some reason this is also navigable (see bug 1118522).
add_connection_test(
"bad.include-subdomains.pinning.example.com..",
MOZILLA_PKIX_ERROR_KEY_PINNING_FAILURE
);
I'm not at all sure how to deal with this. Did you have any tips?
| Reporter | ||
Comment 6•2 years ago
|
||
I think it's because the test adds bad.include-subdomains.pinning.example.com. and bad.include-subdomains.pinning.example.com.. to the list, but when we check we remove the dot from the string we're checking.
If I change the code to be:
localDomain = mLocalDomains.Contains(aHostname);
if (StringEndsWith(aHostname, "."_ns)) {
localDomain = localDomain || mLocalDomains.Contains(
Substring(aHostname, 0, aHostname.Length() - 1));
}
the test passes.
Also we check mLocalDomains in multiple places - I think it would be good to put this in a helper function instead, and call it where necessary.
Comment 8•2 years ago
|
||
| bugherder | ||
Updated•2 years ago
|
Description
•