-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Major - P3
-
Affects Version/s: None
-
Component/s: None
-
None
-
Environment:Compass 1.50.0, Windows 11, Portmaster (Safing) application firewall active
-
2
-
Not Needed
-
None
-
Developer Tools
Description
Connecting to an Atlas cluster through a mongodb+srv:// URI fails with:
MongoParseError: Multiple text records not allowed
The cluster publishes a single TXT record. The local DNS resolver (Portmaster) adds informational TXT records under a different owner name, inf.portmaster, in the additional section of the response. That is allowed by RFC 1035. Raw response to the TXT query:
qd/an/ns/ar: 1, 1, 0, 3
answer <cluster>.xxxxx.mongodb.net TXT "authSource=admin&replicaSet=<cluster>-shard-0"
additional inf.portmaster TXT "accepted: allowing dns request"
additional inf.portmaster TXT "served from cache, resolved by Cloudflare (…)"
additional inf.portmaster TXT "record valid for 1m0s"
Node's dns.resolveTxt() on the same resolver correctly returns only the answer record:
[["authSource=admin&replicaSet=<cluster>-shard-0"]].
Root cause
- devtools-connect resolves SRV/TXT through os-dns-native.withNodeFallback (connect.ts#L161-L190).
- On Windows, os-dns-native iterates over the whole DnsQuery_UTF8 result list (binding.cc#L398-L404) and only filters by record type (index.js#L27-L34). It checks neither the section nor the owner name, so the additional-section TXT records are returned as answers.
- resolve-mongodb-srv then sees 4 TXT records and rejects them (index.ts#L61). That check itself is correct.
- The non-Windows code path already restricts parsing to the answer section (ns_parserr(msg, ns_s_an, …)), so only Windows is affected.
Suggested fix
In os-dns-native's Windows DNSResponse constructor, skip records whose Flags.S.Section != DnsSectionAnswer. Also consider skipping records whose pName does not match the queried name or its CNAME chain.
Steps to reproduce
1. On Windows, use a resolver that adds TXT records to the additional section (e.g. Portmaster).
2. Connect Compass to any Atlas cluster with a mongodb+srv:// URI.
Expected
Connection succeeds. Actual: Multiple text records not allowed.