A domain's NS set comes from whichever server answers first, so it can change between checks when servers disagree #200

Closed
opened 2026-10-02 00:42:09 +02:00 by clawbot · 1 comment
Collaborator

Found while reviewing #199 (random server order, #138).

A domain's NS set (LookupNS, which is FindAuthoritativeNameservers in internal/resolver/iterative.go) is taken from whichever server answers first while following delegations. When those servers disagree about the NS records (during a move between DNS providers, or with a stale secondary), the set depends on which server was asked. With servers tried in a random order, it can change from one check to the next, and an "NS Change" notification goes out each time with no real change.

Definition of done

  • The NS set compared between checks is the same whichever server is asked first. The README says the domain check watches nameservers "added to or removed from the delegation"; the recommended source is the delegation itself, the NS set the parent zone's servers refer to, which they serve alike. If the code shows a better source, say why in the PR.
  • When the parent's delegation and the zone's own NS records disagree, that is not reported as an NS change on every check.
  • A test shows the set does not depend on server order: response data built in the test, or a seeded order (as the work for 138 uses), or live DNS where reliable. No stand-in resolver or client.
  • Lands before #199.

Model: opus-5-5

Found while reviewing https://git.eeqj.de/sneak/dnswatcher/pulls/199 (random server order, https://git.eeqj.de/sneak/dnswatcher/issues/138). A domain's NS set (`LookupNS`, which is `FindAuthoritativeNameservers` in `internal/resolver/iterative.go`) is taken from whichever server answers first while following delegations. When those servers disagree about the NS records (during a move between DNS providers, or with a stale secondary), the set depends on which server was asked. With servers tried in a random order, it can change from one check to the next, and an "NS Change" notification goes out each time with no real change. ## Definition of done - The NS set compared between checks is the same whichever server is asked first. The README says the domain check watches nameservers "added to or removed from the delegation"; the recommended source is the delegation itself, the NS set the parent zone's servers refer to, which they serve alike. If the code shows a better source, say why in the PR. - When the parent's delegation and the zone's own NS records disagree, that is not reported as an NS change on every check. - A test shows the set does not depend on server order: response data built in the test, or a seeded order (as the work for 138 uses), or live DNS where reliable. No stand-in resolver or client. - Lands before https://git.eeqj.de/sneak/dnswatcher/pulls/199. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 00:42:09 +02:00
Author
Collaborator

Built in #202: a domain's NS set is now the delegation its parent zone's servers send for it, so it no longer depends on which of the domain's own servers answered first; those servers are not asked for their NS records any more.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/dnswatcher/pulls/202: a domain's NS set is now the delegation its parent zone's servers send for it, so it no longer depends on which of the domain's own servers answered first; those servers are not asked for their NS records any more. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#200