@@ -192,20 +192,32 @@ jobs:
192192 # Stop any pre-installed dnsmasq instance from the package's default unit.
193193 sudo systemctl stop dnsmasq 2>/dev/null || true
194194 # --no-resolv: ignore /etc/resolv.conf (which on ubuntu-latest points at
195- # systemd-resolved on 127.0.0.53 and would loop back to ourselves on
196- # port 53 if we ever bound there).
197- # Bind to 5353 to avoid colliding with systemd-resolved.
198- sudo dnsmasq --port=5353 \
195+ # systemd-resolved on 127.0.0.53), so we never loop back to ourselves.
196+ # Listen on 127.0.0.1:53: systemd-resolved's stub owns 127.0.0.53:53
197+ # only, so this address is free, and --bind-interfaces keeps us off
198+ # every other one. The tests can then name the resolver as a bare IP,
199+ # which t/087-udp-socket.t TEST 10 needs: it hands
200+ # $TEST_NGINX_RESOLVER to setpeername() with port 53.
201+ # --host-record: --no-hosts keeps /etc/hosts out, and public resolvers
202+ # do not answer "localhost" (RFC 6761 makes it the stub resolver's
203+ # job), so answer it here instead of relying on an outside name.
204+ sudo dnsmasq --port=53 \
199205 --listen-address=127.0.0.1 \
200206 --bind-interfaces \
201207 --no-resolv --no-hosts \
208+ --host-record=localhost,127.0.0.1,::1 \
209+ --host-record=trailing-dot.test,127.0.0.1 \
202210 --server=8.8.4.4 --server=8.8.8.8 --server=1.1.1.1 \
203211 --cache-size=1000 \
204212 --pid-file=/tmp/dnsmasq.pid
213+ sudo ss -lnupt | grep -q '127\.0\.0\.1:53' \
214+ || (echo "ERROR: dnsmasq is not listening on 127.0.0.1:53" >&2; exit 1)
215+ # localhost must resolve locally, or the resolver tests fail.
216+ dig +short @127.0.0.1 localhost
205217 # Warm the cache for all external hostnames the test suite resolves.
206218 for h in openresty.org www.openresty.org agentzh.org sregex.org \
207219 www.google.com google-public-dns-a.google.com; do
208- dig +short +tries=3 +time=2 @127.0.0.1 -p 5353 "$h" || true
220+ dig +short +tries=3 +time=2 @127.0.0.1 "$h" || true
209221 done
210222
211223 - name : Build LuaJIT
@@ -278,8 +290,14 @@ jobs:
278290 export LD_PRELOAD=$PWD/mockeagain/mockeagain.so
279291 export TEST_NGINX_HTTP3_CRT=$PWD/t/cert/http3/http3.crt
280292 export TEST_NGINX_HTTP3_KEY=$PWD/t/cert/http3/http3.key
281- export TEST_NGINX_OPENRESTY_ORG_IP=$(dig +short @127.0.0.1 -p 5353 openresty.org | head -n1)
282- dig +short @127.0.0.1 -p 5353 openresty.org || true
283- dig +short @127.0.0.1 -p 5353 agentzh.org || true
293+ # Resolve through the local dnsmasq cache. Without this the test files
294+ # fall back to their own default of 8.8.8.8, which sends every query
295+ # out to a public resolver -- the very thing the cache is here to
296+ # avoid -- and which cannot answer "localhost", so t/014-bugs.t TEST 37
297+ # and t/058-tcp-socket.t TEST 4 fail.
298+ export TEST_NGINX_RESOLVER=127.0.0.1
299+ export TEST_NGINX_OPENRESTY_ORG_IP=$(dig +short @127.0.0.1 openresty.org | head -n1)
300+ dig +short @127.0.0.1 openresty.org || true
301+ dig +short @127.0.0.1 agentzh.org || true
284302 python3 ./util/nc_server.py &
285303 /usr/bin/env perl $(command -v prove) -I. -Itest-nginx/inc -Itest-nginx/lib -r t/
0 commit comments