From fcea93bd66000c1bea3856c82a25cbdd33b12c38 Mon Sep 17 00:00:00 2001 From: Jamil Date: Wed, 18 Sep 2024 22:50:41 -0700 Subject: [PATCH] revert: "chore(connlib): don't add routes for DNS sentinel servers" (#6775) Reverts firezone/firezone#6755 The problem was that ipv6 dns sentinel range falls outside the dns resources ipv6 range.. --- rust/connlib/tunnel/src/client.rs | 6 +++++- rust/connlib/tunnel/src/tests/sim_client.rs | 22 +++++++++++++++------ 2 files changed, 21 insertions(+), 7 deletions(-) diff --git a/rust/connlib/tunnel/src/client.rs b/rust/connlib/tunnel/src/client.rs index 0788b2483..434b6eb67 100644 --- a/rust/connlib/tunnel/src/client.rs +++ b/rust/connlib/tunnel/src/client.rs @@ -815,6 +815,8 @@ impl ClientState { .map(|(ip, _)| ip) .chain(iter::once(IPV4_RESOURCES.into())) .chain(iter::once(IPV6_RESOURCES.into())) + .chain(iter::once(DNS_SENTINELS_V4.into())) + .chain(iter::once(DNS_SENTINELS_V6.into())) .chain( self.internet_resource .map(|_| Ipv4Network::DEFAULT_ROUTE.into()), @@ -1841,7 +1843,9 @@ mod proptests { resource_routes .into_iter() .chain(iter::once(IPV4_RESOURCES.into())) - .chain(iter::once(IPV6_RESOURCES.into())), + .chain(iter::once(IPV6_RESOURCES.into())) + .chain(iter::once(DNS_SENTINELS_V4.into())) + .chain(iter::once(DNS_SENTINELS_V6.into())), ) } diff --git a/rust/connlib/tunnel/src/tests/sim_client.rs b/rust/connlib/tunnel/src/tests/sim_client.rs index 0142fe949..cfd5c45ad 100644 --- a/rust/connlib/tunnel/src/tests/sim_client.rs +++ b/rust/connlib/tunnel/src/tests/sim_client.rs @@ -947,15 +947,25 @@ fn ref_client( } fn default_routes_v4() -> Vec { - vec![Ipv4Network::new(Ipv4Addr::new(100, 96, 0, 0), 11).unwrap()] + vec![ + Ipv4Network::new(Ipv4Addr::new(100, 96, 0, 0), 11).unwrap(), + Ipv4Network::new(Ipv4Addr::new(100, 100, 111, 0), 24).unwrap(), + ] } fn default_routes_v6() -> Vec { - vec![Ipv6Network::new( - Ipv6Addr::new(0xfd00, 0x2021, 0x1111, 0x8000, 0, 0, 0, 0), - 107, - ) - .unwrap()] + vec![ + Ipv6Network::new( + Ipv6Addr::new(0xfd00, 0x2021, 0x1111, 0x8000, 0, 0, 0, 0), + 107, + ) + .unwrap(), + Ipv6Network::new( + Ipv6Addr::new(0xfd00, 0x2021, 0x1111, 0x8000, 0x0100, 0x0100, 0x0111, 0), + 120, + ) + .unwrap(), + ] } fn known_hosts() -> impl Strategy>> {