Skip to content

consomme: add dns resolver - #2633

Merged
Daman Mulye (damanm24) merged 33 commits into
microsoft:mainfrom
damanm24:dns-unix
Feb 5, 2026
Merged

Daman Mulye (damanm24) merged 33 commits into
microsoft:mainfrom
damanm24:dns-unix

Conversation

@damanm24

Copy link
Copy Markdown
Contributor

This PR changes the manner in which DNS is done in consomme and aligns the implementation closer with what is implemented in WSL.

The current approach to DNS is: the guest uses DHCP to communicate with the host, and the host will pass it's current DNS settings back to the guest (obtained from either /etc/resolv.conf (on linux hosts) and or via the GetAdatpersAddresses Win32 API call (on Windows hosts)). Thus, all DNS requests made from the guest are addressed directly to the same DNS servers that are configured on the host (obviously they are still proxied through consomme).

The new approach is to pass Consomme's self-assigned ip address to the guest via DHCP and resolve the DNS requests by using syscalls available on the host:

  • On windows: DnsQueryRaw
  • On Linux/MacOs: res_send

This is more aligned to how WSL handles DNS today: https://github.com/microsoft/WSL/blob/fdfe1eb8439370c9eb6780467abc1e3f08f90eb1/src/windows/service/exe/DnsResolver.cpp#L9

There is one major follow-up item that will have to be addressed:
DnsQueryRaw is only available on newer releases of Windows 11, so in the event that this function is not available in the dnsapi.dll currently on the system, we will have to fallback to using DnsQueryEx.

To keep the scope of this already large PR manageable, this will be handled in a follow-up PR.

Copilot AI review requested due to automatic review settings January 9, 2026 22:51
@damanm24
Daman Mulye (damanm24) requested review from a team as code owners January 9, 2026 22:51
@github-actions github-actions Bot added the unsafe Related to unsafe code label Jan 9, 2026
@github-actions

github-actions Bot commented Jan 9, 2026

Copy link
Copy Markdown

⚠️ Unsafe Code Detected

This PR modifies files containing unsafe Rust code. Extra scrutiny is required during review.

For more on why we check whole files, instead of just diffs, check out the Rustonomicon

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR implements a new DNS resolution approach for consomme, changing from direct host DNS passthrough to self-hosted resolution using OS syscalls. The implementation uses Windows' DnsQueryRaw API and Unix's res_send libc function, aligning with WSL's DNS handling approach.

Key changes:

  • New DNS resolver infrastructure with platform-specific backends (Windows: DnsQueryRaw, Unix: res_send)
  • Integration of DNS handling into UDP packet processing flow
  • Major dependency update: smoltcp 0.8 → 0.12 with associated API adaptations
  • DHCP server now advertises consomme's gateway IP as DNS server when resolver is available

Reviewed changes

Copilot reviewed 13 out of 14 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
Cargo.toml / Cargo.lock Added heapless, tracelimit dependencies; upgraded smoltcp to 0.12.0 with new transitive dependencies
consomme/build.rs New build script to link resolver library on Unix platforms
consomme/Cargo.toml Added dependencies and Windows API features for DNS implementation
dns/mod.rs Core DNS resolver interface, response queuing, and SERVFAIL response generation
dns/dns_resolver_windows.rs Windows DNS backend using DnsQueryRaw with async callback handling
dns/dns_resolver_unix.rs Unix DNS backend using res_send with dedicated worker thread
dns/delay_load.rs Windows DLL delay-loading for runtime DNS API availability detection
lib.rs DNS resolver initialization and integration into Consomme instance
udp.rs DNS request handling, response sending, and refactored UDP packet building
tcp.rs API updates for smoltcp 0.12 (protocol→next_header, timestamp field, type conversions)
dhcp.rs Updated for smoltcp 0.12 DHCP API changes (heapless::Vec for DNS servers, new fields)
icmp.rs Type conversion updates for Ipv4Address changes
dns_unix.rs Type conversion update in nameserver parsing

Comment thread vm/devices/net/net_consomme/consomme/src/dns/delay_load.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns/delay_load.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns/mod.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/lib.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/udp.rs
Comment thread vm/devices/net/net_consomme/consomme/src/dns/dns_resolver_windows.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns/mod.rs Outdated
@github-actions

github-actions Bot commented Jan 9, 2026

Copy link
Copy Markdown

Comment thread vm/devices/net/net_consomme/consomme/src/dns/delay_load.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns/dns_resolver_unix.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns_resolver/windows/mod.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns/mod.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns/mod.rs Outdated
Daman Mulye (damanm24) added a commit that referenced this pull request Feb 4, 2026
The following PRs: #2633 and #2398 require features that are only
available in a newer version of smoltcp. Since the linked PRs are
already large in size, it makes sense to do the version upgrade and
corresponding build fixes in a separate PR. Unfortunately, there have
been some changes in smoltcp that add bloat to our dependency list.
Despite trying a myriad of combinations to turn off various features, I
wasn't able to reduce the number of requisite dependencies that we have
to pull in as a result of doing this upgrade.
Comment thread vm/devices/net/net_consomme/consomme/src/dns_resolver/windows/mod.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns_resolver/windows/mod.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns_resolver/mod.rs Outdated
"DNS request limit reached, returning SERVFAIL"
);
let response = build_servfail_response(request.dns_query);
self.receiver.sender().send(DnsResponse {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking we would just drop the response and let the guest timeout. Otherwise, this queue can grow without bound.

Comment thread vm/devices/net/net_consomme/consomme/src/dns_resolver/mod.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/udp.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/dns_resolver/mod.rs
Comment thread vm/devices/net/net_consomme/consomme/src/dns_resolver/mod.rs Outdated
Comment thread vm/devices/net/net_consomme/consomme/src/lib.rs Outdated
@damanm24
Daman Mulye (damanm24) merged commit c6b6bbb into microsoft:main Feb 5, 2026
56 checks passed
Daman Mulye (damanm24) added a commit that referenced this pull request Feb 24, 2026
Addressing a follow-up item from: #2633, to fixup pal to move away from
`winapi` usage as it's no longer supported.
Daman Mulye (damanm24) added a commit that referenced this pull request Mar 10, 2026
This PR adds support for DNS over TCP. 

If a TCP connection is being initiated (by the guest), addressed to
consommé's gateway IP on port 53, consommé's TCP module will intercept
the request and instead of creating a socket on the host it will submit
the DNS query on behalf of the guest using the resolver implementation
that was introduced in #2633.

---------

Co-authored-by: Daman Mulye <[email protected]>
Co-authored-by: Daman Mulye <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

unsafe Related to unsafe code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants