DNS_PACKET_PAYLOAD_SIZE_MAX is limiting the size of the stub replies to
512 with EDNS off or 4096 with EDNS on, without checking the protocol
used. This makes TCP replies for clients without EDNS support to be
limited to 512, making the truncate flag useless if the query result is
bigger than 512 bytes.
This commit increases the size of TCP replies to DNS_PACKET_SIZE_MAX
Fixes: #10816
(cherry picked from commit
e6eed9445956cfa496e1db933bfd3530db23bfce)
Gbp-Pq: Name resolved-Increase-size-of-TCP-stub-replies.patch
static inline uint16_t DNS_PACKET_PAYLOAD_SIZE_MAX(DnsPacket *p) {
- /* Returns the advertised maximum datagram size for replies, or the DNS default if there's nothing defined. */
+ /* Returns the advertised maximum size for replies, or the DNS default if there's nothing defined. */
if (p->opt)
return MAX(DNS_PACKET_UNICAST_SIZE_MAX, p->opt->key->class);
+ if (p->ipproto == IPPROTO_TCP)
+ return DNS_PACKET_SIZE_MAX;
+
return DNS_PACKET_UNICAST_SIZE_MAX;
}