https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8431
Vincent Lefevre <[email protected]> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |[email protected] --- Comment #1 from Vincent Lefevre <[email protected]> --- I've tried again with the Inria VPN and using the -D option to get debug messages. When I grep "dns:": Oct 1 10:26:31.175 [998041] dbg: dns: EDNS, UDP payload size 4096 Oct 1 10:26:31.175 [998041] dbg: dns: servers obtained from Net::DNS : [193.51.196.179]:53 Oct 1 10:26:31.175 [998041] dbg: dns: nameservers set to 193.51.196.179 Oct 1 10:26:31.175 [998041] dbg: dns: using socket module: IO::Socket::IP version 0.43 Oct 1 10:26:31.175 [998041] dbg: dns: is Net::DNS::Resolver available? yes Oct 1 10:26:31.175 [998041] dbg: dns: Net::DNS version: 1.57 followed by a succession of "dbg: dns: found CNAME ..." messages... until I stopped the VPN, in which case I no longer get any "dns:" message. I the full debug file, I can see the effect of the timeout, but not a single debug message about the failures. So, there are several issues: * The fact that the learner doesn't check whether the nameservers have changed. Note that this is potentially a security issue if the IP address is a private one, because after a change of network, the IP address may correspond to a different machine. * The missing debug message about the failure. * And I think that sa-learn should terminate after repeated failures. -- You are receiving this mail because: You are the assignee for the bug.
