tests: enable temporary libunbound debug logging
What changed, and why it matters
This commit only adds a temporary debug-logging knob for a DNS library during a unit test. It does not change production behavior, fix a vulnerability, or introduce an obvious security flaw.
No security action required. Treat as routine test/debugging instrumentation.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch exposes ub_ctx_debuglevel through a new DNSResolver::set_debug_level(int) method and calls it in tests/unit_tests/address_from_url.cpp to raise libunbound verbosity during a single failure test, then resets it. The change is test-only and gated by the caller; production code is unaffected.
Changed components
src/common/dns_utils.cppsrc/common/dns_utils.htests/unit_tests/address_from_url.cppInspect captured patch +9 / −0
diff --git a/src/common/dns_utils.cpp b/src/common/dns_utils.cpp
index c890cdb..3412e0d 100644
--- a/src/common/dns_utils.cpp
+++ b/src/common/dns_utils.cpp
@@ -357,6 +357,11 @@ DNSResolver DNSResolver::create()
return DNSResolver();
}
+void DNSResolver::set_debug_level(int level)
+{
+ ub_ctx_debuglevel(m_data->m_ub_context, level);
+}
+
namespace dns_utils
{
diff --git a/src/common/dns_utils.h b/src/common/dns_utils.h
index 334ac8a..97a8f9a 100644
--- a/src/common/dns_utils.h
+++ b/src/common/dns_utils.h
@@ -144,6 +144,8 @@ public:
*/
static DNSResolver create();
+ void set_debug_level(int level);
+
private:
/**
diff --git a/tests/unit_tests/address_from_url.cpp b/tests/unit_tests/address_from_url.cpp
index 35ad28d..ef9b938 100644
--- a/tests/unit_tests/address_from_url.cpp
+++ b/tests/unit_tests/address_from_url.cpp
@@ -109,7 +109,9 @@ TEST(AddressFromURL, Failure)
{
bool dnssec_result = false;
+ tools::DNSResolver::instance().set_debug_level(4);
std::vector<std::string> addresses = tools::dns_utils::addresses_from_url("example.veryinvalid", dnssec_result);
+ tools::DNSResolver::instance().set_debug_level(0);
// for a non-existing domain such as "example.invalid", the non-existence is proved with NSEC records
ASSERT_TRUE(dnssec_result);
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.