26 ms·
Nginx resolver security advisories
- vojtech_kurka 11y agoAfter an upgrade to 1.8.1 our rewrites (alias+regexp+try_files) stopped working.
- lfam 11y agoRelated to this? *) Bugfix: the "try_files" directive inside a nested location given by a regular expression worked incorrectly if the "alias" directive was used in the outer location. from: http://nginx.org/en/CHANGES-1.8 http://nginx.org/en/CHANGES-1.8
- vojtech_kurka 11y agoYes, probably related. I reported it here: https://forum.nginx.org/read.php?11,264181 https://forum.nginx.org/read.php?11,264181
- r1ch 11y agoFrom my read of the docs, try_files expands aliases, so the alias directives in your location blocks are unnecessary, causing nginx to look for /home/mysite/www/js/js/whatever.js
- vojtech_kurka 11y agoYou're right, thank you. The aliases are completely useless. It's just strange to introduce such a change in a "stable" release.
- ak217 11y agoRelated, can anyone explain why nginx uses its own resolver instead of the system one?
- brazzledazzle 11y agoI have no idea if it's substantiated but I've read accusations that it's so you'll pay for the commercial version. Apparently the open source version ignores the TTL and just caches it until you restart the process.
- BraveNewCurency 11y agoI think it's because the system DNS can block under some conditions. That's death for nginx, which can't afford to spin up a thread per request.