mirror of
https://github.com/Control-D-Inc/ctrld.git
synced 2026-07-16 13:17:19 +02:00
cmd/cli: preserve fallback listener port across reload in DNS intercept
On macOS DNS-intercept mode, when mDNSResponder owns *:53 ctrld falls back to listening on 127.0.0.1:5354, and the pf rdr rules correctly redirect DNS to the bound port at startup. However, DNS resolution later breaks with an endless watchdog "anchor intact but probe FAILED -> force reload" loop and `dig @127.0.0.1` timeouts. Root cause is config reload. In CD mode, apiConfigReload refetches the generated config (which always declares port 53) every hour and the reload merge in runWait only inherits the running port when the new port is 0. The generated config explicitly says 53, so `*p.cfg = *newCfg` reverts p.cfg to port 53. The DNS listener goroutines are started only when !reload, so they are never re-bound and stay on 5354. Every subsequent pf rebuild reads p.cfg and targets the dead port 53. Fix: after applying the reloaded config in DNS-intercept mode on darwin, restore the actual bound listener IP/Port into the in-memory config via the new preserveBoundListeners helper, logging the configured-vs-actual divergence. A reload cannot move the running listener anyway, so this keeps p.cfg consistent with reality; all pf rdr rules and the watchdog probe then target the live port. The on-disk generated config is intentionally left unchanged (still 53), so no generated-config change is required.
This commit is contained in:
+11
-1
@@ -1287,7 +1287,7 @@ func tryUpdateListenerConfigIntercept(cfg *ctrld.Config, notifyFunc func(), fata
|
||||
return false, true
|
||||
}
|
||||
|
||||
hasExplicitConfig := lc.IP != "" && lc.IP != "0.0.0.0" && lc.Port != 0
|
||||
hasExplicitConfig := isExplicitInterceptListener(lc.IP, lc.Port)
|
||||
if !hasExplicitConfig {
|
||||
// Set defaults for intercept mode
|
||||
if lc.IP == "" || lc.IP == "0.0.0.0" {
|
||||
@@ -1345,6 +1345,16 @@ func tryUpdateListenerConfigIntercept(cfg *ctrld.Config, notifyFunc func(), fata
|
||||
return updated, false
|
||||
}
|
||||
|
||||
func isExplicitInterceptListener(ip string, port int) bool {
|
||||
if ip == "" || ip == "0.0.0.0" || port == 0 {
|
||||
return false
|
||||
}
|
||||
// 127.0.0.1:53 is the default macOS DNS-intercept listener. It can appear
|
||||
// in generated/custom Control D configs, but it should still be allowed to
|
||||
// fall back to 127.0.0.1:5354 when mDNSResponder already owns port 53.
|
||||
return !(ip == "127.0.0.1" && port == 53)
|
||||
}
|
||||
|
||||
// tryUpdateListenerConfig tries updating listener config with a working one.
|
||||
// If fatal is true, and there's listen address conflicted, the function do
|
||||
// fatal error.
|
||||
|
||||
Reference in New Issue
Block a user