fix: stop forcing port 53 on DoH/DoQ DNS server entries (#5950)

Object-form DNS server entries always received port: 53, because
DnsServerObjectInnerSchema defaulted the port unconditionally and the
DnsServerModal wire adapter always wrote it. Per Xray-core, encrypted
schemes must not carry a port field; a non-standard port is embedded in
the URL instead.

Default the port to 53 only for non-encrypted addresses and omit it for
the encrypted DNS schemes Xray dispatches without a port - https,
https+local, h2c, h2c+local and quic+local - both in the Zod schema and
in the modal's valuesToWire adapter. Schemes are matched
case-insensitively to mirror Xray-core's EqualFold comparison. A shared
isEncryptedDnsAddress helper backs both paths.

Fixes #5920

Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
This commit is contained in:
Matt Van Horn
2026-07-14 03:55:10 -07:00
committed by GitHub
parent 65b5074b60
commit ae0da4c51f
4 changed files with 55 additions and 4 deletions
@@ -41,7 +41,6 @@ exports[`DnsObjectSchema fixtures > parses full byte-stably 1`] = `
"address": "quic+local://dns.adguard.com",
"disableCache": true,
"finalQuery": true,
"port": 53,
"serveExpiredTTL": 60,
"serveStale": false,
"timeoutMs": 5000,