ResolveIPAddresses returns no addresses and no error when every nameserver fails #190

Closed
opened 2026-10-01 22:54:12 +02:00 by clawbot · 1 comment
Collaborator

Found while reviewing #187.

ResolveIPAddresses in internal/resolver/iterative.go reads only the records from each nameserver's answer and ignores its status. When every nameserver of the name's zone times out, fails or refuses, it returns no addresses and no error, which callers cannot tell apart from a name that has no addresses. It does return an error when the walk down from the root fails.

Definition of done

  • When no nameserver of the zone gave a usable answer, ResolveIPAddresses returns an error saying so; a name that really has no addresses still returns none and no error.
  • Callers (port and TLS checks, nameserver addresses) keep their previous state on that error rather than recording "no addresses", and say so in a test or in the PR where a test cannot be reliable.
  • Live-DNS test for the error case against servers that never answer (for example a documentation address), as the resolver timeout test does. No stand-in resolver.

Model: opus-5-5

Found while reviewing https://git.eeqj.de/sneak/dnswatcher/pulls/187. `ResolveIPAddresses` in `internal/resolver/iterative.go` reads only the records from each nameserver's answer and ignores its status. When every nameserver of the name's zone times out, fails or refuses, it returns no addresses and no error, which callers cannot tell apart from a name that has no addresses. It does return an error when the walk down from the root fails. ## Definition of done - When no nameserver of the zone gave a usable answer, `ResolveIPAddresses` returns an error saying so; a name that really has no addresses still returns none and no error. - Callers (port and TLS checks, nameserver addresses) keep their previous state on that error rather than recording "no addresses", and say so in a test or in the PR where a test cannot be reliable. - Live-DNS test for the error case against servers that never answer (for example a documentation address), as the resolver timeout test does. No stand-in resolver. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-01 22:54:12 +02:00
Author
Collaborator

Done in #194. The port and TLS checks do not call ResolveIPAddresses, so the port-state loss they have when every nameserver fails is filed separately as #193.

Model: opus-5-5

Done in https://git.eeqj.de/sneak/dnswatcher/pulls/194. The port and TLS checks do not call `ResolveIPAddresses`, so the port-state loss they have when every nameserver fails is filed separately as https://git.eeqj.de/sneak/dnswatcher/issues/193. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#190