cf-dns: resolve on filter demand

Use separate dns cache entries for addresses (A+AAAA) and HTTPS-RR
results. That makes also "negative" results independent of each other.
Dns cache entries, once in use, can no longer be modified safely, as
concurrent use would require each access then to be done under lock. By
using separate entries, we can update a HTTPS entry without needing to
duplicate an existing address entry for the same host+port.

Connection filters can now ask for DNS resolves. This works at any time
during connection setup and while connect is going on.
`Curl_conn_dns_add_addr_resolve()` and
`Curl_conn_dns_add_https_resolve()` are used for that. They check if the
resolve is already ongoing, can be added to a resolve not started yet
or, as last resort, create a new filter instance and add it to the
connection (it's easier to add more filters than making the same filter
handle multiple resolves. Since DNS filters are removed once the
connection is established, there is no later penalty).

HTTPS-RR queries are added by the `HTTPS-CONNECT`, `SSL` and `QUIC`
filters. The latter will only do that when ECH is configured and
supported. That means we trigger HTTPS-RR queries only when the results
matter.

Add test_22_06 for ALPN influenced via HTTPS-RR when tunneling through a
proxy. This did not work before.

Adjust test2100 to use https: as the previous http: URL no longer
triggers HTTPS-RR resolves.

Closes #22216
This commit is contained in:
Stefan Eissing 2026-07-15 17:21:04 +02:00 committed by Daniel Stenberg
parent c5fd5eb55a
commit 7ad33fe56f
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
31 changed files with 809 additions and 573 deletions

View file

@ -41,6 +41,7 @@ Funny-head: yesyes
<client>
<server>
http
https
</server>
# requires Debug so that it can use the DoH server without https
@ -55,7 +56,7 @@ IPv6
HTTP GET using DoH (with HTTPS RR)
</name>
<command>
http://foo.example.com:%HTTPPORT/%TESTNUMBER --doh-url http://%HOSTIP:%HTTPPORT/%TESTNUMBER0001
https://foo.example.com:%HTTPSPORT/%TESTNUMBER --insecure --doh-insecure --doh-url https://%HOSTIP:%HTTPSPORT/%TESTNUMBER0001
</command>
</client>
@ -71,43 +72,43 @@ s/com\x00\x00(\x1c|\x01)/com-00-00!/g;
<protocol crlf="yes">
%if HTTPSRR
POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPPORT
Accept: */*
Content-Type: application/dns-message
Content-Length: 33
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%03foo%07example%03com-00-00!%00%01]hex%POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPPORT
Accept: */*
Content-Type: application/dns-message
Content-Length: 33
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%03foo%07example%03com-00-00!%00%01]hex%POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPPORT
Host: %HOSTIP:%HTTPSPORT
Accept: */*
Content-Type: application/dns-message
Content-Length: 47
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%06_%HTTPPORT%06_https%03foo%07example%03com%00%00A%00%01]hex%GET /%TESTNUMBER HTTP/1.1
Host: foo.example.com:%HTTPPORT
User-Agent: curl/%VERSION
Accept: */*
%else
POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPPORT
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%06_%HTTPSPORT%06_https%03foo%07example%03com%00%00A%00%01]hex%POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPSPORT
Accept: */*
Content-Type: application/dns-message
Content-Length: 33
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%03foo%07example%03com-00-00!%00%01]hex%POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPPORT
Host: %HOSTIP:%HTTPSPORT
Accept: */*
Content-Type: application/dns-message
Content-Length: 33
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%03foo%07example%03com-00-00!%00%01]hex%GET /%TESTNUMBER HTTP/1.1
Host: foo.example.com:%HTTPPORT
Host: foo.example.com:%HTTPSPORT
User-Agent: curl/%VERSION
Accept: */*
%else
POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPSPORT
Accept: */*
Content-Type: application/dns-message
Content-Length: 33
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%03foo%07example%03com-00-00!%00%01]hex%POST /%TESTNUMBER0001 HTTP/1.1
Host: %HOSTIP:%HTTPSPORT
Accept: */*
Content-Type: application/dns-message
Content-Length: 33
%hex[%00%00%01%00%00%01%00%00%00%00%00%00%03foo%07example%03com-00-00!%00%01]hex%GET /%TESTNUMBER HTTP/1.1
Host: foo.example.com:%HTTPSPORT
User-Agent: curl/%VERSION
Accept: */*

View file

@ -30,7 +30,7 @@ SOCKS5 proxy with too long username
# it should never connect to the target server
<command>
http://hohoho.example.com:99/%TESTNUMBER -x socks5://%repeat[256 x A]%:b@%HOSTIP:%SOCKSPORT
http://localhost:99/%TESTNUMBER -x socks5://%repeat[256 x A]%:b@%HOSTIP:%SOCKSPORT
</command>
</client>