resolver: ask a referral's nameservers that come without addresses (closes #221)
check / check (push) Successful in 1m9s
check / check (push) Successful in 1m9s
Looking up a nameserver's own address followed only the addresses a referral gave, so a nameserver whose zone is delegated without them, such as a.ntpns.org of pool.ntp.org, never resolved. The walk to a name's nameservers looked addresses up only when a referral gave none. Both now go through queryZone, which asks the nameservers whose addresses the referral gives first and, if none of them gives a usable reply, looks up and asks the others. maxLookupDepth stops lookups three deep, so delegations that point at each other still end; when the limit is why no address was found, the error is ErrLookupDepthExceeded, not "no address". Model: opus-5-5
This commit is contained in:
+126
-43
@@ -19,6 +19,16 @@ const (
|
||||
maxRetries = 2
|
||||
maxDelegation = 20
|
||||
timeoutMultiplier = 2
|
||||
|
||||
// maxLookupDepth is how many lookups of nameserver addresses may be
|
||||
// under way one inside another. Looking up a nameserver's address
|
||||
// can meet a referral that names nameservers without their
|
||||
// addresses, which are then looked up in turn; without a limit,
|
||||
// delegations that point at each other would never end. Each level
|
||||
// multiplies the queries sent. pool.ntp.org needs three: the
|
||||
// address of its nameserver g.ntpns.org can need a.ntpns.org's,
|
||||
// which needs a bitnames.com nameserver's.
|
||||
maxLookupDepth = 3
|
||||
)
|
||||
|
||||
// ErrRefused is returned when a DNS server refuses a query.
|
||||
@@ -198,13 +208,15 @@ func (r *Resolver) followDelegation(
|
||||
// servers are the root servers, the servers of zone ".".
|
||||
zone := "."
|
||||
|
||||
var withoutAddresses []string
|
||||
|
||||
for range maxDelegation {
|
||||
if checkCtx(ctx) != nil {
|
||||
return nil, ErrContextCanceled
|
||||
}
|
||||
|
||||
resp, err := r.queryServers(
|
||||
ctx, servers, zone, domain, dns.TypeNS,
|
||||
resp, err := r.queryZone(
|
||||
ctx, servers, withoutAddresses, zone, domain, dns.TypeNS, 0,
|
||||
)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
@@ -229,18 +241,7 @@ func (r *Resolver) followDelegation(
|
||||
return r.resolveNSIterative(ctx, domain)
|
||||
}
|
||||
|
||||
glue := extractGlue(resp.Extra)
|
||||
nextServers := glueIPs(authNS, glue)
|
||||
|
||||
if len(nextServers) == 0 {
|
||||
nextServers = r.resolveNSIPs(ctx, authNS)
|
||||
}
|
||||
|
||||
if len(nextServers) == 0 {
|
||||
return nil, ErrNoNameservers
|
||||
}
|
||||
|
||||
servers = nextServers
|
||||
servers, withoutAddresses = referralNameservers(resp)
|
||||
zone = referralZone(resp)
|
||||
}
|
||||
|
||||
@@ -366,24 +367,110 @@ func nsSetFrom(resp *dns.Msg, domain string) []string {
|
||||
return extractNSSet(resp.Answer)
|
||||
}
|
||||
|
||||
// resolveNSIPs returns the addresses of every nameserver in nsNames
|
||||
// whose name resolves, for a referral that carries none. The walk can
|
||||
// then go on to the zone's other nameservers when one gives no usable
|
||||
// reply.
|
||||
func (r *Resolver) resolveNSIPs(
|
||||
ctx context.Context,
|
||||
nsNames []string,
|
||||
) []string {
|
||||
var ips []string
|
||||
// referralNameservers returns the IPv4 addresses that resp, a referral,
|
||||
// gives for the nameservers it names, and the names of the nameservers
|
||||
// it gives no address for.
|
||||
func referralNameservers(resp *dns.Msg) ([]string, []string) {
|
||||
glue := extractGlue(resp.Extra)
|
||||
|
||||
for _, ns := range nsNames {
|
||||
resolved, err := r.resolveARecord(ctx, ns)
|
||||
var given, withoutAddresses []string
|
||||
|
||||
for _, ns := range extractNSSet(resp.Ns) {
|
||||
ips := glueIPs([]string{ns}, glue)
|
||||
if len(ips) == 0 {
|
||||
withoutAddresses = append(withoutAddresses, ns)
|
||||
}
|
||||
|
||||
given = append(given, ips...)
|
||||
}
|
||||
|
||||
return given, withoutAddresses
|
||||
}
|
||||
|
||||
// queryZone asks the servers of zone about name as queryServers does:
|
||||
// first those at given, the addresses a referral gave, and only when
|
||||
// none of them gives a usable reply, the nameservers named
|
||||
// withoutAddresses, once their addresses are looked up. depth is how
|
||||
// many lookups of a nameserver's address are under way, 0 in the walk
|
||||
// to a domain's nameservers; at maxLookupDepth, no address is looked
|
||||
// up. When the limit is why none was found, here or in a lookup this
|
||||
// one started, the error is ErrLookupDepthExceeded.
|
||||
func (r *Resolver) queryZone(
|
||||
ctx context.Context,
|
||||
given []string,
|
||||
withoutAddresses []string,
|
||||
zone string,
|
||||
name string,
|
||||
qtype uint16,
|
||||
depth int,
|
||||
) (*dns.Msg, error) {
|
||||
err := fmt.Errorf(
|
||||
"no address for any nameserver of %s: %w", zone, ErrNoNameservers,
|
||||
)
|
||||
|
||||
if len(given) > 0 {
|
||||
var resp *dns.Msg
|
||||
|
||||
resp, err = r.queryServers(ctx, given, zone, name, qtype)
|
||||
if err == nil {
|
||||
ips = append(ips, resolved...)
|
||||
return resp, nil
|
||||
}
|
||||
}
|
||||
|
||||
return ips
|
||||
if len(withoutAddresses) == 0 {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
if depth >= maxLookupDepth {
|
||||
return nil, fmt.Errorf(
|
||||
"addresses of the nameservers of %s not looked up: %w",
|
||||
zone, ErrLookupDepthExceeded,
|
||||
)
|
||||
}
|
||||
|
||||
lookedUp, limitErr := r.resolveNSIPs(ctx, withoutAddresses, depth+1)
|
||||
if limitErr != nil {
|
||||
return nil, limitErr
|
||||
}
|
||||
|
||||
if len(lookedUp) == 0 {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return r.queryServers(ctx, lookedUp, zone, name, qtype)
|
||||
}
|
||||
|
||||
// resolveNSIPs returns the addresses of every nameserver in nsNames
|
||||
// whose name resolves, each looked up at depth (see resolveARecord).
|
||||
// The walk can then go on to the zone's other nameservers when one
|
||||
// gives no usable reply. When none resolves and the depth limit
|
||||
// stopped one of the lookups, it returns that lookup's error.
|
||||
func (r *Resolver) resolveNSIPs(
|
||||
ctx context.Context,
|
||||
nsNames []string,
|
||||
depth int,
|
||||
) ([]string, error) {
|
||||
var (
|
||||
ips []string
|
||||
limitErr error
|
||||
)
|
||||
|
||||
for _, ns := range nsNames {
|
||||
resolved, err := r.resolveARecord(ctx, ns, depth)
|
||||
|
||||
switch {
|
||||
case err == nil:
|
||||
ips = append(ips, resolved...)
|
||||
case errors.Is(err, ErrLookupDepthExceeded):
|
||||
limitErr = err
|
||||
}
|
||||
}
|
||||
|
||||
if len(ips) > 0 {
|
||||
return ips, nil
|
||||
}
|
||||
|
||||
return nil, limitErr
|
||||
}
|
||||
|
||||
// resolveNSIterative queries for NS records using iterative
|
||||
@@ -438,11 +525,14 @@ func (r *Resolver) resolveNSIterative(
|
||||
return nil, ErrNoNameservers
|
||||
}
|
||||
|
||||
// resolveARecord resolves a hostname to IPv4 addresses using
|
||||
// iterative resolution through the delegation chain.
|
||||
// resolveARecord resolves a hostname, a nameserver's name, to IPv4
|
||||
// addresses using iterative resolution through the delegation chain.
|
||||
// depth is how many lookups of a nameserver's address are under way,
|
||||
// this one included: 1 for a lookup that no other lookup started.
|
||||
func (r *Resolver) resolveARecord(
|
||||
ctx context.Context,
|
||||
hostname string,
|
||||
depth int,
|
||||
) ([]string, error) {
|
||||
if checkCtx(ctx) != nil {
|
||||
return nil, ErrContextCanceled
|
||||
@@ -452,13 +542,16 @@ func (r *Resolver) resolveARecord(
|
||||
servers := rootServerList()
|
||||
zone := "."
|
||||
|
||||
var withoutAddresses []string
|
||||
|
||||
for range maxDelegation {
|
||||
if checkCtx(ctx) != nil {
|
||||
return nil, ErrContextCanceled
|
||||
}
|
||||
|
||||
resp, err := r.queryServers(
|
||||
ctx, servers, zone, hostname, dns.TypeA,
|
||||
resp, err := r.queryZone(
|
||||
ctx, servers, withoutAddresses, zone, hostname, dns.TypeA,
|
||||
depth,
|
||||
)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf(
|
||||
@@ -485,17 +578,7 @@ func (r *Resolver) resolveARecord(
|
||||
break
|
||||
}
|
||||
|
||||
glue := extractGlue(resp.Extra)
|
||||
nextServers := glueIPs(authNS, glue)
|
||||
|
||||
if len(nextServers) == 0 {
|
||||
// Resolve NS IPs iteratively — but guard
|
||||
// against infinite recursion by using only
|
||||
// already-resolved servers.
|
||||
break
|
||||
}
|
||||
|
||||
servers = nextServers
|
||||
servers, withoutAddresses = referralNameservers(resp)
|
||||
zone = referralZone(resp)
|
||||
}
|
||||
|
||||
@@ -584,7 +667,7 @@ func (r *Resolver) queryNameserver(
|
||||
return nil, ErrContextCanceled
|
||||
}
|
||||
|
||||
nsIPs, err := r.resolveARecord(ctx, nsHostname)
|
||||
nsIPs, err := r.resolveARecord(ctx, nsHostname, 1)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("resolving NS %s: %w", nsHostname, err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user