fix: keep the bypass tunnel's DNS out of resolved #215
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/bypass-dns-59"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem: With double-tunnel mode up,
tunnel_upapplied the alternative servers to the bypass link with the~.routing domain - so both tunnels claimed the default route domain and resolved was free to answer unqualified system queries through either exit (#59).Fix: Only the main role touches resolved, the same rule the hop has followed since #211's era. The bypass link needs no resolved entry at all: bypassed applications resolve through the bypass resolver (dnsmasq), whose upstreams the service already switches when a bypass tunnel is up. The role's dns fields still ride the state update for exactly that switching.
Verification: pinned by test (bypass CONNECTED emits its status, applies nothing to resolved); suite 538 passed. Live check: with main + bypass tunnels both up,
resolvectl domainshould show~.on the main link only, a bypassed app should still resolve, and system DNS should stay on the main tunnel.Closes #59.
🤖 Generated with Claude Code
e8e444ff7cb8045d737eLive-verified 2026-09-16: with main + OpenVPN bypass tunnels up, resolvectl shows the "
." routing domain on tun_aqomui only - the bypass link carries no resolved entry - and bypassed resolution keeps working through dnsmasq (aqomui-bypass curl resolves and returns the bypass exit). First test round was against a build without the fix; both links claimed "." there, confirming the #59 bug live before the fix removed it. Ready to merge.