resolver: a domain's nameservers are only its own delegation (closes #222)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
LookupNS now follows the delegation for the domain alone. When the parent zone's servers answer that it has no delegation, as for a domain that does not exist, the set is empty, and the watcher's NS comparison reports every nameserver removed. FindAuthoritativeNameservers, used for hostnames, still moves to a parent name when the servers answer that the name has no delegation of its own, but returns the error when they do not answer, where it used to take a parent zone's nameservers. The fallback walk treats an authoritative answer the same way. A domain with no delegation still has its own records asked at the servers of the zone it is in. Model: opus-5-5
This commit is contained in:
@@ -88,6 +88,26 @@ func TestFindAuthoritativeNameservers_Subdomain(
|
||||
assert.Equal(t, fromZone, fromHost)
|
||||
}
|
||||
|
||||
// TestFindAuthoritativeNameservers_DelegatedSubdomain looks up the
|
||||
// nameservers of www.cs.cmu.edu, a name in cs.cmu.edu, a zone that
|
||||
// cmu.edu delegates to other servers. The servers of cs.cmu.edu answer
|
||||
// that the name has no delegation of its own, so it gets their names,
|
||||
// not those of the cmu.edu servers. Every referral on the way gives the
|
||||
// nameservers' addresses, so the walk sends few queries.
|
||||
func TestFindAuthoritativeNameservers_DelegatedSubdomain(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
r := newTestResolver(t)
|
||||
fromHost := liveFindAuthoritative(t, r, "www.cs.cmu.edu")
|
||||
fromZone := liveLookupNS(t, r, "cs.cmu.edu")
|
||||
fromParent := liveLookupNS(t, r, "cmu.edu")
|
||||
|
||||
assert.Equal(t, fromZone, fromHost)
|
||||
assert.NotEqual(t, fromParent, fromHost)
|
||||
}
|
||||
|
||||
func TestFindAuthoritativeNameservers_ReturnsSorted(
|
||||
t *testing.T,
|
||||
) {
|
||||
@@ -831,8 +851,7 @@ func TestLookupNS_MatchesFindAuthoritative(t *testing.T) {
|
||||
// nameservers of g.ntpns.org. The org servers delegate its parent zone,
|
||||
// ntpns.org, without the addresses of its nameservers, so the walk has
|
||||
// to look them up to ask them. If it did not, the walk for g.ntpns.org
|
||||
// would fail and LookupNS would return the nameservers of ntpns.org,
|
||||
// which a.ntpns.org is not one of.
|
||||
// would fail.
|
||||
func TestLookupNS_ParentZoneDelegatedWithoutAddresses(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -842,6 +861,33 @@ func TestLookupNS_ParentZoneDelegatedWithoutAddresses(t *testing.T) {
|
||||
assert.Contains(t, nameservers, "a.ntpns.org.")
|
||||
}
|
||||
|
||||
// TestLookupNS_DomainThatDoesNotExist looks up the nameservers of a .com
|
||||
// domain that does not exist. The .com servers answer that it does not
|
||||
// exist, so it has none, and does not get theirs.
|
||||
func TestLookupNS_DomainThatDoesNotExist(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const domain = "dnswatcher-test-does-not-exist.com"
|
||||
|
||||
r := newTestResolver(t)
|
||||
|
||||
var nameservers []string
|
||||
|
||||
livednstest.Retry(
|
||||
t,
|
||||
"LookupNS("+domain+")",
|
||||
func(ctx context.Context) error {
|
||||
var err error
|
||||
|
||||
nameservers, err = r.LookupNS(ctx, domain)
|
||||
|
||||
return err
|
||||
},
|
||||
)
|
||||
|
||||
assert.Empty(t, nameservers)
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------
|
||||
// ResolveIPAddresses tests
|
||||
// ----------------------------------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user