DNS outbound: Replace "reject" with "return" (rCode is 0 by default)

This commit is contained in:
Meow
2026-06-01 06:38:52 +08:00
parent dac4a89607
commit 7de1c73442
3 changed files with 45 additions and 27 deletions
+15 -9
View File
@@ -4,7 +4,7 @@ DNS 是一个出站协议,用于接收由 routing 送入的 DNS 查询,并
此出站只支持传统明文 DNS,即基于 UDP 和 TCP 的查询;DoH、DoT、DoQ 等非传统明文 DNS 不适用于此出站。常见场景是 TUN、透明代理或 `dokodemo-door` 接收到 DNS 流量后,再由 routing 将其分流到此出站。
它可以按规则将查询放行到目标 DNS 服务器、`hijack` 到内置的 [DNS 服务器](../dns.md) 进一步处理、直接丢弃或显式拒绝,也可以改写目标地址、端口和传输协议。
它可以按规则将查询放行到目标 DNS 服务器、`hijack` 到内置的 [DNS 服务器](../dns.md) 进一步处理、直接丢弃或按指定 RCODE 返回响应,也可以改写目标地址、端口和传输协议。
## OutboundConfigurationObject
@@ -16,7 +16,7 @@ DNS 是一个出站协议,用于接收由 routing 送入的 DNS 查询,并
{
// ...
"protocol": "dns",
// [!code focus:17]
// [!code focus:18]
"settings": {
"rewriteNetwork": "udp",
"rewriteAddress": "1.1.1.1",
@@ -24,7 +24,8 @@ DNS 是一个出站协议,用于接收由 routing 送入的 DNS 查询,并
"userLevel": 0,
"rules": [
{
"action": "reject",
"action": "return",
"rCode": 5,
"domain": ["domain:example.com"]
},
{
@@ -63,28 +64,29 @@ DNS 是一个出站协议,用于接收由 routing 送入的 DNS 查询,并
按顺序匹配 DNS 查询规则,并支持按 `qType` 和 `domain` 进行细粒度控制。
若未命中任何规则,则使用内置兜底规则:A 和 AAAA 查询会被导入内置 DNS 模块,其它类型会被显式拒绝。
若未命中任何规则,则使用内置兜底规则:A 和 AAAA 查询会被导入内置 DNS 模块,其它类型会返回空响应,RCODE 为 `0`。
### RuleObject
```json
{
"action": "hijack",
"qType": 1,
"domain": ["geosite:cn"]
"action": "return",
"qType": 65,
"rCode": 5,
"domain": ["domain:example.com"]
}
```
规则中的各匹配条件为与关系;省略某个条件时,表示对此条件不作限制。
> `action`: [ "direct" | "hijack" | "drop" | "reject" ]
> `action`: [ "direct" | "hijack" | "drop" | "return" ]
定义规则命中后的动作。
- `direct`: 直接放行到目标 DNS 服务器;若同时配置了出站级别的 `rewriteNetwork`、`rewriteAddress` 或 `rewritePort`,则按改写后的目标继续转发。
- `hijack`: 将查询导入内置的 [DNS 服务器](../dns.md) 继续处理,可用于按照内置 DNS 的配置进一步分流;目前仅支持 A 和 AAAA 记录。
- `drop`: 直接丢弃请求,不返回响应。
- `reject`: 返回显式拒绝响应,相比 `drop` 可以避免部分应用长时间等待 DNS 超时或反复重试。
- `return`: 返回一个 DNS 响应,响应码由 `rCode` 指定;相比 `drop` 可以避免部分应用长时间等待 DNS 超时或反复重试。
> `qType`: number | string
@@ -95,6 +97,10 @@ DNS 是一个出站协议,用于接收由 routing 送入的 DNS 查询,并
具体数字编号可参考 [IANA 文档](https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml)。
> `rCode`: number
返回响应时使用的 DNS RCODE,范围为 `0` 到 `65535`。仅在 `action` 为 `return` 时生效;未指定时默认为 `0`。
> `domain`: [string]
匹配域名列表,写法与 [路由规则中的 `domain`](../routing.md#ruleobject) 一致。
+15 -9
View File
@@ -4,7 +4,7 @@ DNS is an outbound protocol used to receive DNS queries sent in by routing, then
This outbound only supports traditional plaintext DNS queries over UDP and TCP; non-plaintext DNS protocols such as DoH, DoT, and DoQ are not applicable to this outbound. Common scenarios include TUN, transparent proxy, or `dokodemo-door` receiving DNS traffic and then routing sending that traffic to this outbound.
It can allow queries to the target DNS server, `hijack` them to the built-in [DNS server](../dns.md) for further processing, drop them, or explicitly refuse them according to rules. It can also rewrite the target address, port, and transport protocol.
It can allow queries to the target DNS server, `hijack` them to the built-in [DNS server](../dns.md) for further processing, drop them, or return responses with a specified RCODE according to rules. It can also rewrite the target address, port, and transport protocol.
## OutboundConfigurationObject
@@ -16,7 +16,7 @@ It can allow queries to the target DNS server, `hijack` them to the built-in [DN
{
// ...
"protocol": "dns",
// [!code focus:17]
// [!code focus:18]
"settings": {
"rewriteNetwork": "udp",
"rewriteAddress": "1.1.1.1",
@@ -24,7 +24,8 @@ It can allow queries to the target DNS server, `hijack` them to the built-in [DN
"userLevel": 0,
"rules": [
{
"action": "reject",
"action": "return",
"rCode": 5,
"domain": ["domain:example.com"]
},
{
@@ -63,28 +64,29 @@ The value of `userLevel` corresponds to the `level` value in [policy](../policy.
Matches DNS query rules in order, and supports fine-grained control by `qType` and `domain`.
If no rule is matched, the built-in fallback rule is used: A and AAAA queries are imported into the built-in DNS module, while other query types are explicitly refused.
If no rule is matched, the built-in fallback rule is used: A and AAAA queries are imported into the built-in DNS module, while other query types return an empty response with RCODE `0`.
### RuleObject
```json
{
"action": "hijack",
"qType": 1,
"domain": ["geosite:cn"]
"action": "return",
"qType": 65,
"rCode": 5,
"domain": ["domain:example.com"]
}
```
All matching conditions in a rule are combined with AND logic. If a condition is omitted, that condition is not restricted.
> `action`: [ "direct" | "hijack" | "drop" | "reject" ]
> `action`: [ "direct" | "hijack" | "drop" | "return" ]
Defines the action to take when the rule matches.
- `direct`: Allows the query directly to the target DNS server. If outbound-level `rewriteNetwork`, `rewriteAddress`, or `rewritePort` is also configured, the query is forwarded to the rewritten target.
- `hijack`: Imports the query into the built-in [DNS server](../dns.md) for further processing. This can be used for additional routing based on the built-in DNS configuration. Currently, only A and AAAA records are supported.
- `drop`: Drops the request directly without returning a response.
- `reject`: Returns an explicit refusal response. Compared with `drop`, this can prevent some applications from waiting too long for a DNS timeout or repeatedly retrying.
- `return`: Returns a DNS response whose response code is specified by `rCode`. Compared with `drop`, this can prevent some applications from waiting too long for a DNS timeout or repeatedly retrying.
> `qType`: number | string
@@ -95,6 +97,10 @@ Matches DNS query types. The forms are as follows:
For specific type numbers, refer to the [IANA documentation](https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml).
> `rCode`: number
The DNS RCODE used when returning a response, in the range `0` to `65535`. It only takes effect when `action` is `return`; if omitted, it defaults to `0`.
> `domain`: [string]
Matches a list of domains. The syntax is the same as [`domain` in routing rules](../routing.md#ruleobject).
+15 -9
View File
@@ -4,7 +4,7 @@ DNS — это исходящий протокол, который приним
Этот outbound поддерживает только традиционный открытый DNS, то есть запросы по UDP и TCP; нестандартные для него варианты, такие как DoH, DoT и DoQ, к этому outbound не применимы. Типичные сценарии: TUN, прозрачный прокси или `dokodemo-door` принимают DNS-трафик, после чего routing направляет его в этот outbound.
По правилам он может пропускать запросы к целевому DNS-серверу, выполнять `hijack` во встроенный [DNS-сервер](../dns.md) для дальнейшей обработки, отбрасывать запросы или явно отказывать в них. Также он может изменять целевой адрес, порт и транспортный протокол.
По правилам он может пропускать запросы к целевому DNS-серверу, выполнять `hijack` во встроенный [DNS-сервер](../dns.md) для дальнейшей обработки, отбрасывать запросы или возвращать ответы с указанным RCODE. Также он может изменять целевой адрес, порт и транспортный протокол.
## OutboundConfigurationObject
@@ -16,7 +16,7 @@ DNS — это исходящий протокол, который приним
{
// ...
"protocol": "dns",
// [!code focus:17]
// [!code focus:18]
"settings": {
"rewriteNetwork": "udp",
"rewriteAddress": "1.1.1.1",
@@ -24,7 +24,8 @@ DNS — это исходящий протокол, который приним
"userLevel": 0,
"rules": [
{
"action": "reject",
"action": "return",
"rCode": 5,
"domain": ["domain:example.com"]
},
{
@@ -63,28 +64,29 @@ DNS — это исходящий протокол, который приним
DNS-запросы сопоставляются с правилами по порядку; поддерживается детальное управление по `qType` и `domain`.
Если ни одно правило не совпало, используется встроенное правило по умолчанию: запросы A и AAAA направляются во встроенный DNS-модуль, а запросы других типов явно отклоняются.
Если ни одно правило не совпало, используется встроенное правило по умолчанию: запросы A и AAAA направляются во встроенный DNS-модуль, а запросы других типов получают пустой ответ с RCODE `0`.
### RuleObject
```json
{
"action": "hijack",
"qType": 1,
"domain": ["geosite:cn"]
"action": "return",
"qType": 65,
"rCode": 5,
"domain": ["domain:example.com"]
}
```
Все условия сопоставления внутри правила объединяются логикой AND. Если условие не указано, ограничение по этому условию не применяется.
> `action`: [ "direct" | "hijack" | "drop" | "reject" ]
> `action`: [ "direct" | "hijack" | "drop" | "return" ]
Определяет действие при совпадении правила.
- `direct`: напрямую пропускает запрос к целевому DNS-серверу. Если на уровне outbound также настроены `rewriteNetwork`, `rewriteAddress` или `rewritePort`, запрос пересылается к измененной цели.
- `hijack`: направляет запрос во встроенный [DNS-сервер](../dns.md) для дальнейшей обработки. Это можно использовать для дополнительного разделения трафика через конфигурацию встроенного DNS. В настоящее время поддерживаются только записи A и AAAA.
- `drop`: напрямую отбрасывает запрос и не возвращает ответ.
- `reject`: возвращает явный отказ. По сравнению с `drop`, это может предотвратить долгое ожидание DNS timeout или повторные попытки у некоторых приложений.
- `return`: возвращает DNS-ответ, код которого задается через `rCode`. По сравнению с `drop`, это может предотвратить долгое ожидание DNS timeout или повторные попытки у некоторых приложений.
> `qType`: number | string
@@ -95,6 +97,10 @@ DNS-запросы сопоставляются с правилами по по
Конкретные номера типов смотрите в [документации IANA](https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml).
> `rCode`: number
DNS RCODE, используемый при возврате ответа, в диапазоне от `0` до `65535`. Действует только когда `action` имеет значение `return`; если не указан, по умолчанию используется `0`.
> `domain`: [string]
Сопоставляет список доменов. Синтаксис такой же, как у [`domain` в правилах routing](../routing.md#ruleobject).