From e53d332eca1d5fc09cc73e3db9a5abb9a3d04aee Mon Sep 17 00:00:00 2001 From: David Fifield Date: Thu, 16 Apr 2020 20:43:03 -0600 Subject: [PATCH] Reduce response delay to 1 s. To be below the reported Quad9 timeout. --- dnstt-server/main.go | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/dnstt-server/main.go b/dnstt-server/main.go index f90d465..d10f4bb 100644 --- a/dnstt-server/main.go +++ b/dnstt-server/main.go @@ -46,6 +46,16 @@ const ( // reflects the overhead of encoding data into a TXT RR. We leave some // slack in case of IPv6 extension headers or non-Ethernet links. maxEncodedPayload = 1100 + + // How long we may wait for downstream data before sending an empty + // response. If another query comes in while we are waiting, we'll send + // an empty response anyway and restart the delay timer for the next + // response. + // + // This number should be less than 2 seconds, which in 2019 was reported + // to be the query timeout of the Quad9 DoH server. + // https://dnsencryption.info/imc19-doe.html Section 4.2, Finding 2.4 + maxResponseDelay = 1 * time.Second ) // A base32 encoding without padding. @@ -415,7 +425,7 @@ func sendLoop(dnsConn net.PacketConn, ttConn *turbotunnel.QueuePacketConn, ch <- } nextP = nil - timer := time.NewTimer(2 * time.Second) + timer := time.NewTimer(maxResponseDelay) loop: for { select { @@ -442,9 +452,10 @@ func sendLoop(dnsConn net.PacketConn, ttConn *turbotunnel.QueuePacketConn, ch <- default: select { case nextRec = <-ch: - // If there's another response waiting - // to be sent, wait no longer for a - // payload for this one. + // If there's another response + // waiting to be sent, wait no + // longer for a payload for this + // one. break loop case <-timer.C: break loop