Fork TLSConfig for each encrypted connection (#5710)

* Fork TLSConfig for each encrypted connection

Signed-off-by: sanyo <sanyo0714@163.com>
Co-authored-by: sanyo <yeshengan.ysa@alibaba-inc.com>
This commit is contained in:
sanyo0714 2022-10-29 00:55:41 +08:00 committed by GitHub
parent 575825a156
commit 9497644505
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 52 additions and 29 deletions

View file

@ -2,45 +2,66 @@ package test
import (
"crypto/tls"
"fmt"
"testing"
"github.com/miekg/dns"
)
func TestDNSoverTLS(t *testing.T) {
corefile := `tls://.:1053 {
func TestTLS(t *testing.T) {
tempCorefile := `%s {
tls ../plugin/tls/test_cert.pem ../plugin/tls/test_key.pem
whoami
}`
qname := "example.com."
qtype := dns.TypeA
dot, doh := ":1053", ":8443"
m := new(dns.Msg)
m.SetQuestion("example.com.", dns.TypeA)
answerLength := 0
ex, _, tcp, err := CoreDNSServerAndPorts(corefile)
if err != nil {
t.Fatalf("Could not get CoreDNS serving instance: %s", err)
}
defer ex.Stop()
m := new(dns.Msg)
m.SetQuestion(qname, qtype)
client := dns.Client{
Net: "tcp-tls",
TLSConfig: &tls.Config{InsecureSkipVerify: true},
}
r, _, err := client.Exchange(m, tcp)
if err != nil {
t.Fatalf("Could not exchange msg: %s", err)
tests := []struct {
server string
tlsConfig *tls.Config
}{
{fmt.Sprintf("tls://.%s", dot),
&tls.Config{InsecureSkipVerify: true},
},
{fmt.Sprintf("tls://.%s", dot),
&tls.Config{InsecureSkipVerify: true, NextProtos: []string{"dot"}},
},
{fmt.Sprintf("tls://.%s https://.%s", dot, doh),
&tls.Config{InsecureSkipVerify: true},
},
{fmt.Sprintf("tls://.%s https://.%s", dot, doh),
&tls.Config{InsecureSkipVerify: true, NextProtos: []string{"dot"}},
},
}
if n := len(r.Answer); n != answerLength {
t.Fatalf("Expected %v answers, got %v", answerLength, n)
}
if n := len(r.Extra); n != 2 {
t.Errorf("Expected 2 RRs in additional section, but got %d", n)
}
if r.Rcode != dns.RcodeSuccess {
t.Errorf("Expected success but got %d", r.Rcode)
for _, tc := range tests {
ex, _, _, err := CoreDNSServerAndPorts(fmt.Sprintf(tempCorefile, tc.server))
if err != nil {
t.Fatalf("Could not get CoreDNS serving instance: %s", err)
}
client := dns.Client{
Net: "tcp-tls",
TLSConfig: tc.tlsConfig,
}
r, _, err := client.Exchange(m, dot)
if err != nil {
t.Fatalf("Could not exchange msg: %s", err)
}
if n := len(r.Answer); n != answerLength {
t.Fatalf("Expected %v answers, got %v", answerLength, n)
}
if n := len(r.Extra); n != 2 {
t.Errorf("Expected 2 RRs in additional section, but got %d", n)
}
if r.Rcode != dns.RcodeSuccess {
t.Errorf("Expected success but got %d", r.Rcode)
}
ex.Stop()
}
}