Skip to content
  • Thomas Haller's avatar
    Revert "dns: change default DNS priority of VPNs to -50" · 034db883
    Thomas Haller authored
    Revert this change. One problem is that none of the current GUIs
    (nm-connection-editor, gnome-control-center, plasma-nm) expose the
    dns-priority option. So, users tend to have their profile value set to
    0. Changing the default means for them not only a change in behavior,
    but its hard to fix via the GUI.
    
    Also, what other call DNS leaks, is Split DNS to some. Both uses make
    sense, but have conflicting goals. The default cannot accommodate both
    at the same time.
    
    Also, with split DNS enabled (dnsmasq, systemd-resolved), the concern
    for DNS leaks is smaller. Imagine:
    
      Wi-Fi profile with ipv4.dns-priority (effectively) 100, domain "example.com".
      VPN profile with ipv4.dns-priority (effectively) 50 and a default route.
    
    That is a common setup that one gets by default (and what probably many
    users have today). In such a case with split DNS enabled, the Wi-Fi's DNS
    server only sees requests for "*.example.com". So, it does not leak
    everything.
    
    Hence, revert this change before 1.28.0 release to the earlier behavior.
    
    This reverts commit af13081b.
    
    !688
    (cherry picked from commit ff71bbdc)
    034db883
To find the state of this project's repository at the time of any of these versions, check out the tags.