resolver: never resend a refused query asking for recursion (closes #206)
check / check (push) Successful in 1m32s
check / check (push) Successful in 1m32s
queryDNS resent a query that a server refused, this time asking for recursion, so on a network that intercepts DNS the answers could come from a recursive resolver without anyone knowing. A refusal is now only a refusal, and the server is passed over for the next. When every server of a zone refuses, the error says so. When every root server refuses, the error is ErrIntercepted: root servers refuse no query, so something on the network is answering in their place. FindAuthoritativeNameservers stops at that error instead of trying each parent name, so the watcher's log line says it. A live test asks Quad9, which refuses a query not asking for recursion, so that the resend cannot come back unnoticed. Model: opus-5-5
This commit is contained in:
@@ -19,6 +19,8 @@ trial run of the finished image: https://git.eeqj.de/sneak/dnswatcher/issues/149
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-02: a query a server refuses is not resent asking for recursion, and
|
||||
every root server refusing is reported as DNS interception (closes #206).
|
||||
- 2026-10-02: a push to a branch cancels that branch's older CI run, and the
|
||||
checkout leaves no token in `.git/config` (closes #216).
|
||||
- 2026-10-02: watcher tests send far fewer queries and a live attempt may take
|
||||
|
||||
Reference in New Issue
Block a user