resolver: look up every nameserver a referral gives no address for (closes #221)
check / check (push) Canceled after 0s

Looking up a nameserver's own address followed only the addresses a
referral gave, so a nameserver whose zone is delegated without them,
such as a.ntpns.org of pool.ntp.org, never resolved. The walk to a
name's nameservers looked addresses up only when a referral gave none,
so when it gave some it asked only those. Both now ask every
nameserver a referral names, looking up the addresses it lacks.

A lookup can start further lookups; maxLookupDepth stops them two
deep, so zones delegated to each other's nameservers, as desec.io and
desec.org are, still end. A referral that gives addresses for only
some nameservers now costs one lookup per nameserver without one.

Model: opus-5-5
This commit is contained in:
2026-10-02 05:54:36 +00:00
parent a18803ff28
commit 75b313b4f6
5 changed files with 175 additions and 24 deletions
+6 -2
View File
@@ -411,8 +411,12 @@ In steps 2 and 3 the servers are asked one at a time in a random order, chosen
anew each time, so no one root server gets every first query. A server that does
not reply, refuses the query, or gives an error reply such as SERVFAIL or a
referral that leads no closer to the name is passed over for the next one. When
a referral names a zone's nameservers without their addresses, the addresses of
all of them are looked up, so that each can be asked.
a referral names a zone's nameservers without their addresses, or gives
addresses for only some of them, the addresses of the others are looked up, so
that each can be asked. This holds both in the walk to a name's nameservers and
in the lookup of a nameserver's own address. Such a lookup may need others in
turn; lookups go at most two deep, one inside another, so delegations that point
at each other still end.
This approach ensures: