[PR #6183] [MERGED] [client] Filter DNS fallback upstreams matching our server IP to prevent loops #29133

Open
opened 2026-08-05 08:07:30 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6183
Author: @lixmal
Created: 5/17/2026
Status: Merged
Merged: 6/9/2026
Merged by: @lixmal

Base: mainHead: fix-dns-fallback-self-loop


📝 Commits (1)

  • 94a8b73 Filter DNS fallback upstreams matching our server IP to prevent loops

📊 Changes

1 file changed (+13 additions, -7 deletions)

View changed files

📝 client/internal/dns/server.go (+13 -7)

📄 Description

Describe your changes

Skip any captured original nameserver that matches our own DNS listener IP when building the PriorityFallback upstream handler. Without this, hosts whose /etc/resolv.conf happened to list the NetBird tunnel IPcaused the fallback handler to race DNS queries against itself, producing a DNS loop.

  • Filter s.service.RuntimeIP() out of the fallback upstream list
  • Bail through clearFallback() if filtering leaves no usable upstreams, so no empty handler gets registered

#6182

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Internal bug fix in DNS fallback path, no user-facing API or behavior to document.

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Bug Fixes
    • Fixed DNS fallback handling to properly exclude the server's own IP address from the fallback nameserver list, improving DNS resolution reliability in scenarios where fallback servers are needed.

Review Change Stack


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6183 **Author:** [@lixmal](https://github.com/lixmal) **Created:** 5/17/2026 **Status:** ✅ Merged **Merged:** 6/9/2026 **Merged by:** [@lixmal](https://github.com/lixmal) **Base:** `main` ← **Head:** `fix-dns-fallback-self-loop` --- ### 📝 Commits (1) - [`94a8b73`](https://github.com/netbirdio/netbird/commit/94a8b7325e083d811059e297c013cfe2f7878bfb) Filter DNS fallback upstreams matching our server IP to prevent loops ### 📊 Changes **1 file changed** (+13 additions, -7 deletions) <details> <summary>View changed files</summary> 📝 `client/internal/dns/server.go` (+13 -7) </details> ### 📄 Description ## Describe your changes Skip any captured original nameserver that matches our own DNS listener IP when building the PriorityFallback upstream handler. Without this, hosts whose `/etc/resolv.conf` happened to list the NetBird tunnel IPcaused the fallback handler to race DNS queries against itself, producing a DNS loop. - Filter `s.service.RuntimeIP()` out of the fallback upstream list - Bail through `clearFallback()` if filtering leaves no usable upstreams, so no empty handler gets registered ## Issue ticket number and link #6182 ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) Internal bug fix in DNS fallback path, no user-facing API or behavior to document. ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed DNS fallback handling to properly exclude the server's own IP address from the fallback nameserver list, improving DNS resolution reliability in scenarios where fallback servers are needed. <!-- review_stack_entry_start --> [![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/netbirdio/netbird/pull/6183?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:07:30 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29133