When FindAuthoritativeNameservers in internal/resolver/iterative.go looks for the servers of a zone, it gives up on the zone if the first of its servers asked answers SERVFAIL or only refers the query onward, even when the zone's other servers would answer. The lookup then fails, or (since #190) returns an error, because of one bad server. Once #138 tries servers in a random order, which server is first changes on every lookup, so this turns into intermittent failures for any zone with one misbehaving server.
Definition of done
A SERVFAIL, a refusal or a referral from one of a zone's servers while finding the zone moves on to that zone's next server, as a timeout already does; the search gives up on the zone only when none of its servers gave a usable answer.
A test shows it, with response data built in the test passed to the step that decides, or live DNS where a reliable case exists. No stand-in resolver or client.
Lands after #194; coordinate with the work for #138 in the same file.
Model: opus-5-5
Found while reviewing https://git.eeqj.de/sneak/dnswatcher/pulls/194.
When `FindAuthoritativeNameservers` in `internal/resolver/iterative.go` looks for the servers of a zone, it gives up on the zone if the first of its servers asked answers SERVFAIL or only refers the query onward, even when the zone's other servers would answer. The lookup then fails, or (since https://git.eeqj.de/sneak/dnswatcher/issues/190) returns an error, because of one bad server. Once https://git.eeqj.de/sneak/dnswatcher/issues/138 tries servers in a random order, which server is first changes on every lookup, so this turns into intermittent failures for any zone with one misbehaving server.
## Definition of done
- A SERVFAIL, a refusal or a referral from one of a zone's servers while finding the zone moves on to that zone's next server, as a timeout already does; the search gives up on the zone only when none of its servers gave a usable answer.
- A test shows it, with response data built in the test passed to the step that decides, or live DNS where a reliable case exists. No stand-in resolver or client.
- Lands after https://git.eeqj.de/sneak/dnswatcher/pulls/194; coordinate with the work for https://git.eeqj.de/sneak/dnswatcher/issues/138 in the same file.
Model: opus-5-5
clawbot
added this to the 1.0 milestone 2026-10-02 00:26:25 +02:00
Built in #201: a SERVFAIL, another error reply, or a referral that does not lead below the zone of the servers asked now moves on to that zone's next server; the zone is given up only when none of its servers gave a usable reply.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/dnswatcher/pulls/201: a SERVFAIL, another error reply, or a referral that does not lead below the zone of the servers asked now moves on to that zone's next server; the zone is given up only when none of its servers gave a usable reply.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while reviewing #194.
When
FindAuthoritativeNameserversininternal/resolver/iterative.golooks for the servers of a zone, it gives up on the zone if the first of its servers asked answers SERVFAIL or only refers the query onward, even when the zone's other servers would answer. The lookup then fails, or (since #190) returns an error, because of one bad server. Once #138 tries servers in a random order, which server is first changes on every lookup, so this turns into intermittent failures for any zone with one misbehaving server.Definition of done
Model: opus-5-5
Built in #201: a SERVFAIL, another error reply, or a referral that does not lead below the zone of the servers asked now moves on to that zone's next server; the zone is given up only when none of its servers gave a usable reply.
Model: opus-5-5