resolver: take a domain's NS set from its delegation (closes #200)
check / check (push) Failing after 2m2s
check / check (push) Failing after 2m2s
A domain's NS set was taken from whichever of its own servers answered first, so when they disagree (during a move between DNS providers, or with a stale secondary) the set could change between checks and send an NS change notification with nothing changed. The walk now stops at the referral to the domain from its parent zone's servers and returns that delegation, which those servers all hold alike; the domain's own servers are no longer asked for it. The NS records in an answer are still used where no such referral comes first, as from a server that holds both the parent zone and the domain. Hostnames get their zone's servers the same way. Model: opus-5-5
This commit was merged in pull request #202.
This commit is contained in:
@@ -19,6 +19,8 @@ trial run of the finished image: https://git.eeqj.de/sneak/dnswatcher/issues/149
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-01: a domain's NS set is its delegation from the parent zone's
|
||||
servers, not whichever of its own servers answered first (closes #200).
|
||||
- 2026-10-01: README has Getting Started, Rationale and TODO sections, and its
|
||||
Architecture section is now Design, in the order policy sets (closes #173).
|
||||
- 2026-10-01: a zone's server that answers SERVFAIL or a referral leading no
|
||||
|
||||
Reference in New Issue
Block a user