Finding a zone's servers gives up after the first server answers SERVFAIL or refers onward #197

Closed
opened 2026-10-02 00:26:25 +02:00 by clawbot · 1 comment
Collaborator

Found while reviewing #194.

When FindAuthoritativeNameservers in internal/resolver/iterative.go looks for the servers of a zone, it gives up on the zone if the first of its servers asked answers SERVFAIL or only refers the query onward, even when the zone's other servers would answer. The lookup then fails, or (since #190) returns an error, because of one bad server. Once #138 tries servers in a random order, which server is first changes on every lookup, so this turns into intermittent failures for any zone with one misbehaving server.

Definition of done

  • A SERVFAIL, a refusal or a referral from one of a zone's servers while finding the zone moves on to that zone's next server, as a timeout already does; the search gives up on the zone only when none of its servers gave a usable answer.
  • A test shows it, with response data built in the test passed to the step that decides, or live DNS where a reliable case exists. No stand-in resolver or client.
  • Lands after #194; coordinate with the work for #138 in the same file.

Model: opus-5-5

Found while reviewing https://git.eeqj.de/sneak/dnswatcher/pulls/194. When `FindAuthoritativeNameservers` in `internal/resolver/iterative.go` looks for the servers of a zone, it gives up on the zone if the first of its servers asked answers SERVFAIL or only refers the query onward, even when the zone's other servers would answer. The lookup then fails, or (since https://git.eeqj.de/sneak/dnswatcher/issues/190) returns an error, because of one bad server. Once https://git.eeqj.de/sneak/dnswatcher/issues/138 tries servers in a random order, which server is first changes on every lookup, so this turns into intermittent failures for any zone with one misbehaving server. ## Definition of done - A SERVFAIL, a refusal or a referral from one of a zone's servers while finding the zone moves on to that zone's next server, as a timeout already does; the search gives up on the zone only when none of its servers gave a usable answer. - A test shows it, with response data built in the test passed to the step that decides, or live DNS where a reliable case exists. No stand-in resolver or client. - Lands after https://git.eeqj.de/sneak/dnswatcher/pulls/194; coordinate with the work for https://git.eeqj.de/sneak/dnswatcher/issues/138 in the same file. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 00:26:25 +02:00
Author
Collaborator

Built in #201: a SERVFAIL, another error reply, or a referral that does not lead below the zone of the servers asked now moves on to that zone's next server; the zone is given up only when none of its servers gave a usable reply.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/dnswatcher/pulls/201: a SERVFAIL, another error reply, or a referral that does not lead below the zone of the servers asked now moves on to that zone's next server; the zone is given up only when none of its servers gave a usable reply. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#197