1 Commits
Author SHA1 Message Date
sneak 7bd8eddba9 resolver: never resend a refused query asking for recursion (closes #206)
check / check (push) Failing after 2m28s
queryDNS resent a query that a server refused, this time asking for
recursion, so on a network that intercepts DNS the answers could come
from a recursive resolver without anyone knowing. A refusal is now only
a refusal, and the server is passed over for the next.

When every server of a zone refuses, the error says so. When every root
server refuses, the error is ErrIntercepted: root servers refuse no
query, so something on the network is answering in their place.
FindAuthoritativeNameservers stops at that error instead of trying each
parent name, so the watcher's log line says it.

A live test asks Quad9, which refuses a query not asking for recursion,
so that the resend cannot come back unnoticed.

Model: opus-5-5
2026-10-02 02:39:17 +00:00
+3 -11
View File
@@ -341,21 +341,13 @@ func TestQueryNameserverIP_RecursiveResolverRefused(t *testing.T) {
}
// googleNameserverIPv4s returns the IPv4 addresses of google.com's
// nameservers. The resolver asks servers only at their IPv4 addresses.
// nameservers, the only addresses the resolver asks servers at.
func googleNameserverIPv4s(t *testing.T, r *resolver.Resolver) []string {
t.Helper()
var servers []string
names := liveFindAuthoritative(t, r, "google.com")
for _, ns := range liveFindAuthoritative(t, r, "google.com") {
for _, ip := range liveResolveIPs(t, r, ns) {
if net.ParseIP(ip).To4() != nil {
servers = append(servers, ip)
}
}
}
return servers
return liveResolveNSIPs(t, r, names, len(names))
}
// TestQueryServers_EveryServerRefused asks all of google.com's