[PR #6441] [client] Surface DNS forwarder upstream failures via Extended DNS Errors #28221

Closed
opened 2026-08-05 08:05:59 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/6441

State: closed
Merged: Yes


Describe your changes

When a domain route's DNS forwarder fails to resolve a query, the client only saw a bare SERVFAIL and had to cross-reference the routing peer's logs to learn why. This attaches an Extended DNS Error (RFC 8914) to forwarder failure responses describing the class of failure, and surfaces it on the querying client so the cause is visible in one place.

  • Forwarder tags upstream-failure responses as timeout or generic failure with an EDE option, without exposing the upstream resolver address
  • Uses codes from the RFC 8914 Private Use range so they never collide with a real upstream EDE
  • DNS interceptor advertises EDNS0 to the forwarder, records any returned EDE in the response trace, and strips the OPT for clients that did not request EDNS0
  • Move the shared OPT-stripping helper and an EDE extractor into the resutil package

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Internal diagnostic surfaced in client trace logs; no user-facing configuration or API change.

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • New Features

    • Added RFC 8914 Extended DNS Error support so upstream failures can return richer DNS error details when the client uses EDNS0.
    • When a client does not send EDNS0, the system still enables upstream EDE generation internally while ensuring responses don’t include EDNS0/OPT payloads.
  • Refactor

    • Centralized OPT stripping logic for consistent behavior across DNS resolution paths.
  • Tests

    • Expanded coverage to validate EDE presence/absence, correct error metadata, and proper failover behavior.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/6441 **State:** closed **Merged:** Yes --- ## Describe your changes When a domain route's DNS forwarder fails to resolve a query, the client only saw a bare SERVFAIL and had to cross-reference the routing peer's logs to learn why. This attaches an Extended DNS Error (RFC 8914) to forwarder failure responses describing the class of failure, and surfaces it on the querying client so the cause is visible in one place. - Forwarder tags upstream-failure responses as timeout or generic failure with an EDE option, without exposing the upstream resolver address - Uses codes from the RFC 8914 Private Use range so they never collide with a real upstream EDE - DNS interceptor advertises EDNS0 to the forwarder, records any returned EDE in the response trace, and strips the OPT for clients that did not request EDNS0 - Move the shared OPT-stripping helper and an EDE extractor into the resutil package ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [x] Is a feature enhancement - [ ] It is a refactor - [x] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) Internal diagnostic surfaced in client trace logs; no user-facing configuration or API change. ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added RFC 8914 Extended DNS Error support so upstream failures can return richer DNS error details when the client uses EDNS0. * When a client does not send EDNS0, the system still enables upstream EDE generation internally while ensuring responses don’t include EDNS0/OPT payloads. * **Refactor** * Centralized OPT stripping logic for consistent behavior across DNS resolution paths. * **Tests** * Expanded coverage to validate EDE presence/absence, correct error metadata, and proper failover behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 08:05:59 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#28221