resolver: try servers in a random order on each resolution (closes #138)
check / check (push) Successful in 1m42s

Every resolution walked the root servers in a fixed order, so
a.root-servers.net got every first query and its timeouts were paid on
every lookup. Each list of servers the resolver walks is now walked in a
random order from rand.Shuffle, chosen anew each time; a server that does
not reply, refuses, or gives an error reply or a referral that leads no
closer is still passed over for the next. When a referral names a zone's
nameservers without their addresses, all of them are now looked up, not
only the first that resolves, so the zone is not given up because the
first nameserver whose address was found gave no usable reply. No test
fails if the walk stops shuffling: which server a live query reached is
not observable.

Model: opus-5-5
This commit was merged in pull request #199.
This commit is contained in:
2026-10-02 03:26:06 +02:00
parent af81f2ac76
commit 82836b41fd
8 changed files with 146 additions and 14 deletions
+7
View File
@@ -407,6 +407,13 @@ it watches. Instead, it performs full iterative resolution:
4. **Authoritative query**: Queries all discovered authoritative nameservers
directly for the requested records.
In steps 2 and 3 the servers are asked one at a time in a random order, chosen
anew each time, so no one root server gets every first query. A server that does
not reply, refuses the query, or gives an error reply such as SERVFAIL or a
referral that leads no closer to the name is passed over for the next one. When
a referral names a zone's nameservers without their addresses, the addresses of
all of them are looked up, so that each can be asked.
This approach ensures:
- Independence from any upstream resolver's cache or filtering.