aboutgitcodebugslistschat
path: root/conf.c
diff options
context:
space:
mode:
authorDavid Gibson <david@gibson.dropbear.id.au>2022-07-06 17:28:56 +1000
committerStefano Brivio <sbrivio@redhat.com>2022-07-14 01:32:42 +0200
commitaa8603e6a9ae4b057e209ad6dfa2be86b8586617 (patch)
treeb11d1c51acdcd5d7607c1e12ff34c28bc5962e92 /conf.c
parent4d777144fd214bf67153f1dfa8e1e7b52b44ae35 (diff)
downloadpasst-aa8603e6a9ae4b057e209ad6dfa2be86b8586617.tar
passt-aa8603e6a9ae4b057e209ad6dfa2be86b8586617.tar.gz
passt-aa8603e6a9ae4b057e209ad6dfa2be86b8586617.tar.bz2
passt-aa8603e6a9ae4b057e209ad6dfa2be86b8586617.tar.lz
passt-aa8603e6a9ae4b057e209ad6dfa2be86b8586617.tar.xz
passt-aa8603e6a9ae4b057e209ad6dfa2be86b8586617.tar.zst
passt-aa8603e6a9ae4b057e209ad6dfa2be86b8586617.zip
Handle the case of a DNS server on localhost
By default, passt detects the nameserver used by the host system by reading /etc/resolv.conf, and advertises that to the guest via DHCP. However this breaks down if the host's nameserver is local (on 127.0.0.1 or ::1); connecting to localhost on the guest won't reach the host's nameserver. Using a local nameserver is a reasonably common case when using dnsmasq or similar to merge name resolution on a home network with name resolution from an organization-private VPN. We already have the gateway mapping support to allow reaching host-local services from the guest via the address of the default gateway. Add code to detect the case of a local DNS server and use the gateway mapping to advertise it usefully to the guest. Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
Diffstat (limited to 'conf.c')
-rw-r--r--conf.c16
1 files changed, 16 insertions, 0 deletions
diff --git a/conf.c b/conf.c
index 22949fd..13cb5a1 100644
--- a/conf.c
+++ b/conf.c
@@ -350,6 +350,14 @@ static void get_dns(struct ctx *c)
if (!dns4_set &&
dns4 - &c->dns4[0] < ARRAY_SIZE(c->dns4) - 1 &&
inet_pton(AF_INET, p + 1, dns4)) {
+ /* We can only access local addresses via the gw redirect */
+ if (ntohl(*dns4) >> IN_CLASSA_NSHIFT == IN_LOOPBACKNET) {
+ if (c->no_map_gw) {
+ *dns4 = 0;
+ continue;
+ }
+ *dns4 = c->gw4;
+ }
dns4++;
*dns4 = 0;
}
@@ -357,6 +365,14 @@ static void get_dns(struct ctx *c)
if (!dns6_set &&
dns6 - &c->dns6[0] < ARRAY_SIZE(c->dns6) - 1 &&
inet_pton(AF_INET6, p + 1, dns6)) {
+ /* We can only access local addresses via the gw redirect */
+ if (IN6_IS_ADDR_LOOPBACK(dns6)) {
+ if (c->no_map_gw) {
+ memset(dns6, 0, sizeof(*dns6));
+ continue;
+ }
+ memcpy(dns6, &c->gw6, sizeof(*dns6));
+ }
dns6++;
memset(dns6, 0, sizeof(*dns6));
}