Apply Pi-Hole blocking to CNAMEs

I implemented CNAME during-the-path blocking for branch new/internal-blocking. This is the branch allowing also per-client blocking rules.

There are two points worth mentioning:

  1. Blocked replies are currently replied to with NODATA instead of the configured blocking mode (technical limitation, which does not yet hurt at this point).
  2. More tests are outstanding.

One of the tests I did:

  • Removed f7ds.liberation.fr from gravity
  • Added atc.eulerian.net to my exact blacklist

Result:

$ dig f7ds.liberation.fr

; <<>> DiG 9.10.3-P4-Debian <<>> f7ds.liberation.fr
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 42224
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;f7ds.liberation.fr.            IN      A

;; Query time: 19 msec
;; SERVER: ::1#53(::1)
;; WHEN: Mon Nov 25 12:59:54 CET 2019
;; MSG SIZE  rcvd: 47