From fc27d3f4e555dee574a94402d85e440348f08fb7 Mon Sep 17 00:00:00 2001 From: Phil Davis Date: Wed, 31 Jul 2013 01:53:11 -0700 Subject: [PATCH] Reorder reverse lookup overrides so user-specified ones are effective If the user specifies a domain override for 10.in-addr.arpa and also specifies "Do not forward private reverse lookups" then the user-specified entry is not effective. But the code was supposed to allow users to specify individual reverse lookup domain overrides that took precedence. Re-ordering the placement of the --server entries on the dnsmasq command line fixes this. Forum: http://forum.pfsense.org/index.php/topic,64986.0.html --- etc/inc/services.inc | 22 ++++++++++++---------- 1 file changed, 12 insertions(+), 10 deletions(-) diff --git a/etc/inc/services.inc b/etc/inc/services.inc index a3c457fa9f..80408acb8d 100644 --- a/etc/inc/services.inc +++ b/etc/inc/services.inc @@ -1669,16 +1669,9 @@ function services_dnsmasq_configure() { } } - /* Setup forwarded domains */ - if (isset($config['dnsmasq']['domainoverrides']) && is_array($config['dnsmasq']['domainoverrides'])) { - foreach($config['dnsmasq']['domainoverrides'] as $override) { - if ($override['ip'] == "!") - $override[ip] = ""; - $args .= ' --server=/' . $override['domain'] . '/' . $override['ip']; - } - } - - /* If selected, then forward reverse lookups for private IPv4 addresses to nowhere. */ + /* If selected, then first forward reverse lookups for private IPv4 addresses to nowhere. */ + /* If any of these are duplicated by a user-specified domain override (e.g. 10.in-addr.arpa) then */ + /* the user-specified entry made later on the command line below will be the one that is effective. */ if (isset($config['dnsmasq']['no_private_reverse'])) { /* Note: Carrier Grade NAT (CGN) addresses 100.64.0.0/10 are intentionally not here. */ /* End-users should not be aware of CGN addresses, so reverse lookups for these should not happen. */ @@ -1691,6 +1684,15 @@ function services_dnsmasq_configure() { } } + /* Setup forwarded domains */ + if (isset($config['dnsmasq']['domainoverrides']) && is_array($config['dnsmasq']['domainoverrides'])) { + foreach($config['dnsmasq']['domainoverrides'] as $override) { + if ($override['ip'] == "!") + $override[ip] = ""; + $args .= ' --server=/' . $override['domain'] . '/' . $override['ip']; + } + } + /* Allow DNS Rebind for forwarded domains */ if (isset($config['dnsmasq']['domainoverrides']) && is_array($config['dnsmasq']['domainoverrides'])) { if(!isset($config['system']['webgui']['nodnsrebindcheck'])) {