[Dnsmasq-discuss] [PATCH 0/2] Stop forwarding queries for names that only exist locally

Dominik Derigs git at dl6er.de
Sun Oct 4 11:44:20 UTC 2026


From: DL6ER <dl6er at dl6er.de>

Hi Simon,

a name in /etc/hosts with only an A record has its AAAA, MX and HTTPS queries forwarded upstream. Where the same name also exists publicly the client gets the public answer, and getaddrinfo() prefers that AAAA over the local A, so the override quietly stops overriding. dig A looks perfectly healthy, which is what makes this hard to diagnose.

--local=/domain/ is the documented answer, but it takes over a whole zone and answers NXDOMAIN for every name in it which is not configured locally. That rules it out for a domain which also exists publicly, which is exactly the split-DNS case where local records are wanted.

Patch 1 adds --local-hosts as the per-name equivalent: a query is answered as an empty NOERROR when dnsmasq holds a record for that exact name and none of the queried type, and is forwarded unchanged otherwise. Other names in the same domain keep being forwarded as usual. The option is off by default. DS and DNSKEY are always forwarded, as an address record says nothing about the keys of the zone the name sits in.

Patch 2 does not depend on the option and fixes something --hostsdir has on its own. add_hosts_entry() links a new record in through cache_hash() without a conflict scan, so an answer cached from upstream before the record appeared is served beside it until its TTL runs out, and clients load-balance across the two. The patch drops the non-local entries for that name first, on the incremental path only - a bulk read happens before any query is answered.

Both are against current master (2.93-33-g03fd0c1).

Reported downstream in https://github.com/pi-hole/FTL/issues/2841, where --local=/name/ is currently the documented answer. Pi-hole now generates those lines itself in https://github.com/pi-hole/FTL/pull/3037, which is what --local-hosts would let us drop.

Best regards,
Dominik

DL6ER (2):
  Add `--local-hosts` to stop forwarding queries for local names
  Drop cached answers when a hosts file read at runtime claims the name

 man/dnsmasq.8 | 20 +++++++++++++++++++
 src/cache.c   | 55 ++++++++++++++++++++++++++++++++++++++++++++++++++-
 src/dnsmasq.h |  5 ++++-
 src/forward.c | 16 +++++++++++++++
 src/option.c  |  3 +++
 src/rfc1035.c | 39 ++++++++++++++++++++++++++----------
 6 files changed, 126 insertions(+), 12 deletions(-)

-- 
2.43.0




More information about the Dnsmasq-discuss mailing list