4 ms·
I’m the author of this. Fun to see it appear here a few years after I wrote it. I originally put this together in an attempt to fish for a Rust gig. It worked o
by oxymoron 6y ago
I’m the author of this. Fun to see it appear here a few years after I wrote it. I originally put this together in an attempt to fish for a Rust gig. It worked out! I current coworker of mine saw it in /r/rust and passed my name to their recruiter.
I’ve felt at times that this project is a bit dated in that it uses synchronous io. I’ve changed my mind about that though. It’s more about teaching DNS than about teaching rust, and async is complex enough that it’d be a pedagogical impedement. Synchronous rust, on the other hand, is very simple to grasp.
- fanf2 6y agoThe first thing I check in DNS software is whether there is a trivial denial of service attack in the name decompression code. Sadly this code fails :-( It is vital that you have a limit on the number of label pointers that you follow, either by ensuring the pointer points to an earlier point in the packet, or by limiting the number of indirections.
- oxymoron 6y agoYeah, it was pointed out by someone on /r/rust when I first posted it. I thought I had corrected that, but apparently not. I’ll revise that tonight. It’s obviously a bad mistake.
- fanf2 6y agoDNS name (de)compression is super tricky and even experts get it wrong in production code, so it's a forgivable mistake :-) It's an interesting trap/pitfall, though, because it's an example of a situation where basic memory safety isn't enough. I would love to see some examples of how to use Rust's type system to protect against DNS name compression loops, e.g. using a slice of the packet to force compression pointers to go backwards.
- oxymoron 6y agoTook me a few days before I could get to it, but this has been fixed now.