ExportXMLWordPrintableJSON

    • Type: Bug
    • Resolution: Fixed
    • Priority: Major - P3
    • 1.52.0
    • Affects Version/s: None
    • Component/s: None
    • None
    • Environment:
      Compass 1.50.0, Windows 11, Portmaster (Safing) application firewall active
    • 2
    • Not Needed
    • None
    • Developer Tools

      Description

      Connecting to an Atlas cluster through a mongodb+srv:// URI fails with:

      MongoParseError: Multiple text records not allowed

      The cluster publishes a single TXT record. The local DNS resolver (Portmaster) adds informational TXT records under a different owner name, inf.portmaster, in the additional section of the response. That is allowed by RFC 1035. Raw response to the TXT query:

      qd/an/ns/ar: 1, 1, 0, 3
      answer      <cluster>.xxxxx.mongodb.net  TXT  "authSource=admin&replicaSet=<cluster>-shard-0"
      additional  inf.portmaster               TXT  "accepted: allowing dns request"
      additional  inf.portmaster               TXT  "served from cache, resolved by Cloudflare (…)"
      additional  inf.portmaster               TXT  "record valid for 1m0s"

      Node's dns.resolveTxt() on the same resolver correctly returns only the answer record:
      [["authSource=admin&replicaSet=<cluster>-shard-0"]].

      Root cause

      • devtools-connect resolves SRV/TXT through os-dns-native.withNodeFallback (connect.ts#L161-L190).
      • On Windows, os-dns-native iterates over the whole DnsQuery_UTF8 result list (binding.cc#L398-L404) and only filters by record type (index.js#L27-L34). It checks neither the section nor the owner name, so the additional-section TXT records are returned as answers.
      • resolve-mongodb-srv then sees 4 TXT records and rejects them (index.ts#L61). That check itself is correct.
      • The non-Windows code path already restricts parsing to the answer section (ns_parserr(msg, ns_s_an, …)), so only Windows is affected.

        Suggested fix

      In os-dns-native's Windows DNSResponse constructor, skip records whose Flags.S.Section != DnsSectionAnswer. Also consider skipping records whose pName does not match the queried name or its CNAME chain.

      Steps to reproduce

      1. On Windows, use a resolver that adds TXT records to the additional section (e.g. Portmaster).
      2. Connect Compass to any Atlas cluster with a mongodb+srv:// URI.

      Expected

      Connection succeeds. Actual: Multiple text records not allowed.

            Assignee:
            Neal Beeken
            Reporter:
            Jérôme Senot (EXT)
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: