ResolveIPAddresses in internal/resolver/iterative.go reads only the records from each nameserver's answer and ignores its status. When every nameserver of the name's zone times out, fails or refuses, it returns no addresses and no error, which callers cannot tell apart from a name that has no addresses. It does return an error when the walk down from the root fails.
Definition of done
When no nameserver of the zone gave a usable answer, ResolveIPAddresses returns an error saying so; a name that really has no addresses still returns none and no error.
Callers (port and TLS checks, nameserver addresses) keep their previous state on that error rather than recording "no addresses", and say so in a test or in the PR where a test cannot be reliable.
Live-DNS test for the error case against servers that never answer (for example a documentation address), as the resolver timeout test does. No stand-in resolver.
Model: opus-5-5
Found while reviewing https://git.eeqj.de/sneak/dnswatcher/pulls/187.
`ResolveIPAddresses` in `internal/resolver/iterative.go` reads only the records from each nameserver's answer and ignores its status. When every nameserver of the name's zone times out, fails or refuses, it returns no addresses and no error, which callers cannot tell apart from a name that has no addresses. It does return an error when the walk down from the root fails.
## Definition of done
- When no nameserver of the zone gave a usable answer, `ResolveIPAddresses` returns an error saying so; a name that really has no addresses still returns none and no error.
- Callers (port and TLS checks, nameserver addresses) keep their previous state on that error rather than recording "no addresses", and say so in a test or in the PR where a test cannot be reliable.
- Live-DNS test for the error case against servers that never answer (for example a documentation address), as the resolver timeout test does. No stand-in resolver.
Model: opus-5-5
clawbot
added this to the 1.0 milestone 2026-10-01 22:54:12 +02:00
Done in #194. The port and TLS checks do not call ResolveIPAddresses, so the port-state loss they have when every nameserver fails is filed separately as #193.
Model: opus-5-5
Done in https://git.eeqj.de/sneak/dnswatcher/pulls/194. The port and TLS checks do not call `ResolveIPAddresses`, so the port-state loss they have when every nameserver fails is filed separately as https://git.eeqj.de/sneak/dnswatcher/issues/193.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while reviewing #187.
ResolveIPAddressesininternal/resolver/iterative.goreads only the records from each nameserver's answer and ignores its status. When every nameserver of the name's zone times out, fails or refuses, it returns no addresses and no error, which callers cannot tell apart from a name that has no addresses. It does return an error when the walk down from the root fails.Definition of done
ResolveIPAddressesreturns an error saying so; a name that really has no addresses still returns none and no error.Model: opus-5-5
Done in #194. The port and TLS checks do not call
ResolveIPAddresses, so the port-state loss they have when every nameserver fails is filed separately as #193.Model: opus-5-5