resolver: look up every nameserver a referral gives no address for (closes #221)
check / check (push) Canceled after 0s

Looking up a nameserver's own address followed only the addresses a
referral gave, so a nameserver whose zone is delegated without them,
such as a.ntpns.org of pool.ntp.org, never resolved. The walk to a
name's nameservers looked addresses up only when a referral gave none,
so when it gave some it asked only those. Both now ask every
nameserver a referral names, looking up the addresses it lacks.

A lookup can start further lookups; maxLookupDepth stops them two
deep, so zones delegated to each other's nameservers, as desec.io and
desec.org are, still end. A referral that gives addresses for only
some nameservers now costs one lookup per nameserver without one.

Model: opus-5-5
This commit is contained in:
2026-10-02 05:54:36 +00:00
parent a18803ff28
commit 75b313b4f6
5 changed files with 175 additions and 24 deletions
+12 -2
View File
@@ -48,12 +48,22 @@ func (r *Resolver) QueryEachNS(
return r.queryEachNS(ctx, nameservers, hostname, recordTypes())
}
// ResolveNSIPs exports resolveNSIPs for testing.
// ResolveNSIPs exports resolveNSIPs for testing, looking each name up
// as a lookup that no other lookup started.
func (r *Resolver) ResolveNSIPs(
ctx context.Context,
nsNames []string,
) []string {
return r.resolveNSIPs(ctx, nsNames)
return r.resolveNSIPs(ctx, nsNames, 1)
}
// ReferralServers exports referralServers for testing, for a referral
// met in the walk to a domain's nameservers.
func (r *Resolver) ReferralServers(
ctx context.Context,
resp *dns.Msg,
) []string {
return r.referralServers(ctx, resp, 0)
}
// RootServerList exports rootServerList for testing.