By default, passt detects the nameserver used by the host system by reading /etc/resolv.conf, and advertises that to the guest via DHCP. However this breaks down if the host's nameserver is local (on 127.0.0.1 or ::1); connecting to localhost on the guest won't reach the host's nameserver. Using a local nameserver is a reasonably common case when using dnsmasq or similar to merge name resolution on a home network with name resolution from an organization-private VPN. We already have the gateway mapping support to allow reaching host-local services from the guest via the address of the default gateway. Add code to detect the case of a local DNS server and use the gateway mapping to advertise it usefully to the guest. Signed-off-by: David Gibson <david(a)gibson.dropbear.id.au> --- conf.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/conf.c b/conf.c index 22949fd..13cb5a1 100644 --- a/conf.c +++ b/conf.c @@ -350,6 +350,14 @@ static void get_dns(struct ctx *c) if (!dns4_set && dns4 - &c->dns4[0] < ARRAY_SIZE(c->dns4) - 1 && inet_pton(AF_INET, p + 1, dns4)) { + /* We can only access local addresses via the gw redirect */ + if (ntohl(*dns4) >> IN_CLASSA_NSHIFT == IN_LOOPBACKNET) { + if (c->no_map_gw) { + *dns4 = 0; + continue; + } + *dns4 = c->gw4; + } dns4++; *dns4 = 0; } @@ -357,6 +365,14 @@ static void get_dns(struct ctx *c) if (!dns6_set && dns6 - &c->dns6[0] < ARRAY_SIZE(c->dns6) - 1 && inet_pton(AF_INET6, p + 1, dns6)) { + /* We can only access local addresses via the gw redirect */ + if (IN6_IS_ADDR_LOOPBACK(dns6)) { + if (c->no_map_gw) { + memset(dns6, 0, sizeof(*dns6)); + continue; + } + memcpy(dns6, &c->gw6, sizeof(*dns6)); + } dns6++; memset(dns6, 0, sizeof(*dns6)); } -- 2.36.1