https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8431

Vincent Lefevre <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #1 from Vincent Lefevre <[email protected]> ---
I've tried again with the Inria VPN and using the -D option to get debug
messages. When I grep "dns:":

Oct  1 10:26:31.175 [998041] dbg: dns: EDNS, UDP payload size 4096
Oct  1 10:26:31.175 [998041] dbg: dns: servers obtained from Net::DNS :
[193.51.196.179]:53
Oct  1 10:26:31.175 [998041] dbg: dns: nameservers set to 193.51.196.179
Oct  1 10:26:31.175 [998041] dbg: dns: using socket module: IO::Socket::IP
version 0.43
Oct  1 10:26:31.175 [998041] dbg: dns: is Net::DNS::Resolver available? yes
Oct  1 10:26:31.175 [998041] dbg: dns: Net::DNS version: 1.57

followed by a succession of "dbg: dns: found CNAME ..." messages... until I
stopped the VPN, in which case I no longer get any "dns:" message. I the full
debug file, I can see the effect of the timeout, but not a single debug message
about the failures.

So, there are several issues:
  * The fact that the learner doesn't check whether the nameservers have
changed. Note that this is potentially a security issue if the IP address is a
private one, because after a change of network, the IP address may correspond
to a different machine.
  * The missing debug message about the failure.
  * And I think that sa-learn should terminate after repeated failures.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to