Found while reviewing #199 (random server order, #138).
A domain's NS set (LookupNS, which is FindAuthoritativeNameservers in internal/resolver/iterative.go) is taken from whichever server answers first while following delegations. When those servers disagree about the NS records (during a move between DNS providers, or with a stale secondary), the set depends on which server was asked. With servers tried in a random order, it can change from one check to the next, and an "NS Change" notification goes out each time with no real change.
Definition of done
The NS set compared between checks is the same whichever server is asked first. The README says the domain check watches nameservers "added to or removed from the delegation"; the recommended source is the delegation itself, the NS set the parent zone's servers refer to, which they serve alike. If the code shows a better source, say why in the PR.
When the parent's delegation and the zone's own NS records disagree, that is not reported as an NS change on every check.
A test shows the set does not depend on server order: response data built in the test, or a seeded order (as the work for 138 uses), or live DNS where reliable. No stand-in resolver or client.
Found while reviewing https://git.eeqj.de/sneak/dnswatcher/pulls/199 (random server order, https://git.eeqj.de/sneak/dnswatcher/issues/138).
A domain's NS set (`LookupNS`, which is `FindAuthoritativeNameservers` in `internal/resolver/iterative.go`) is taken from whichever server answers first while following delegations. When those servers disagree about the NS records (during a move between DNS providers, or with a stale secondary), the set depends on which server was asked. With servers tried in a random order, it can change from one check to the next, and an "NS Change" notification goes out each time with no real change.
## Definition of done
- The NS set compared between checks is the same whichever server is asked first. The README says the domain check watches nameservers "added to or removed from the delegation"; the recommended source is the delegation itself, the NS set the parent zone's servers refer to, which they serve alike. If the code shows a better source, say why in the PR.
- When the parent's delegation and the zone's own NS records disagree, that is not reported as an NS change on every check.
- A test shows the set does not depend on server order: response data built in the test, or a seeded order (as the work for 138 uses), or live DNS where reliable. No stand-in resolver or client.
- Lands before https://git.eeqj.de/sneak/dnswatcher/pulls/199.
Model: opus-5-5
clawbot
added this to the 1.0 milestone 2026-10-02 00:42:09 +02:00
Built in #202: a domain's NS set is now the delegation its parent zone's servers send for it, so it no longer depends on which of the domain's own servers answered first; those servers are not asked for their NS records any more.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/dnswatcher/pulls/202: a domain's NS set is now the delegation its parent zone's servers send for it, so it no longer depends on which of the domain's own servers answered first; those servers are not asked for their NS records any more.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while reviewing #199 (random server order, #138).
A domain's NS set (
LookupNS, which isFindAuthoritativeNameserversininternal/resolver/iterative.go) is taken from whichever server answers first while following delegations. When those servers disagree about the NS records (during a move between DNS providers, or with a stale secondary), the set depends on which server was asked. With servers tried in a random order, it can change from one check to the next, and an "NS Change" notification goes out each time with no real change.Definition of done
Model: opus-5-5
Built in #202: a domain's NS set is now the delegation its parent zone's servers send for it, so it no longer depends on which of the domain's own servers answered first; those servers are not asked for their NS records any more.
Model: opus-5-5
clawbot referenced this issue2026-10-02 01:36:55 +02:00