net/dns/publicdns: don't upgrade Control D port-53-only addresses to DoH (#20463)

DoHEndpointFromIP mapped the entire 2606:1a40::/48 range to a
dns.controld.com/<id> DoH URL, but the ID-encoded addresses in that range
are legacy plaintext-DNS endpoints that refuse :443. They now fall through
as ordinary port-53 resolvers; the free anycast freedns.controld.com/pN
addresses still upgrade via exact match.

Fixes #20433

Signed-off-by: Brendan Creane <bcreane@gmail.com>
This commit is contained in:
Brendan Creane
2026-07-17 15:33:17 -07:00
committed by GitHub
parent 689c6c2e6d
commit d2af6a4d39
3 changed files with 60 additions and 13 deletions
+12 -2
View File
@@ -146,9 +146,19 @@ func TestResolversWithDelays(t *testing.T) {
want: o("https://dns.nextdns.io/c3a884"),
},
{
name: "controld-ipv6-expand",
// ID-encoded Control D addresses are legacy port-53-only
// endpoints (see #20433); they must not be upgraded to DoH and
// instead pass through as ordinary port-53 resolvers.
name: "controld-ipv6-id-encoded-not-doh",
in: q("2606:1a40:0:6:7b5b:5949:35ad:0"),
want: o("https://dns.controld.com/hyq3ipr2ct"),
want: o("2606:1a40:0:6:7b5b:5949:35ad:0"),
},
{
// The free anycast resolvers (freedns.controld.com/pN) do serve
// DoH and are upgraded.
name: "controld-free-anycast-doh",
in: q("2606:1a40::1"),
want: o("https://freedns.controld.com/p1", "2606:1a40::1+0.5s"),
},
{
name: "controld-doh-input",