Nameservers that a referral names without addresses are not looked up, so pool.ntp.org cannot be watched #221

Closed
opened 2026-10-02 07:35:28 +02:00 by clawbot · 1 comment
Collaborator

Found in the trial run for #149.

The README says: "When a referral names a zone's nameservers without their addresses, the addresses of all of them are looked up, so that each can be asked" (DNS Resolution Strategy). Two lookups do not do this.

A nameserver's own address. To ask a watched name's nameservers for its records, dnswatcher first looks up each nameserver's address, following referrals from the root servers, and gives up when a referral gives no addresses. pool.ntp.org is served by a.ntpns.org. to i.ntpns.org., and the .org servers delegate ntpns.org to nameservers in other zones (ns1.us.bitnames.com., anyns.pch.net. and others) without addresses. So every nameserver of pool.ntp.org is saved with status error and the reason resolving NS a.ntpns.org.: cannot resolve a.ntpns.org.: no authoritative nameservers found, and the name gets no records, ports or certificates. The reason is also wrong: ntpns.org has nameservers whose addresses were never looked up. This is resolveARecord in internal/resolver/iterative.go, which leaves its loop when the referral carries no addresses.

A referral with some addresses. When a referral gives addresses for some of the nameservers it names, the walk to a name's nameservers asks only those and never looks up the rest. The .org servers' referral for ntp.org names four nameservers but gives an address for ns1.everett.org. alone, so the walk to pool.ntp.org depends on that one server answering. This is followDelegation in the same file, which looks up addresses only when the referral gives none.

Definition of done

  • Both lookups follow a referral by asking every nameserver it names: those it gives addresses for, and the others once their addresses are looked up. Delegations that point at each other still end.
  • Watching pool.ntp.org shows its nameservers a.ntpns.org. to i.ntpns.org. with status ok and their records.
  • Tests against live DNS, no stand-in resolver: a nameserver name whose zone is delegated without addresses, such as a.ntpns.org, resolves; the walk to a name under ntp.org can use its nameservers that the .org referral gives no address for.

Model: opus-5-5

Found in the trial run for https://git.eeqj.de/sneak/dnswatcher/issues/149. The README says: "When a referral names a zone's nameservers without their addresses, the addresses of all of them are looked up, so that each can be asked" (DNS Resolution Strategy). Two lookups do not do this. **A nameserver's own address.** To ask a watched name's nameservers for its records, dnswatcher first looks up each nameserver's address, following referrals from the root servers, and gives up when a referral gives no addresses. `pool.ntp.org` is served by `a.ntpns.org.` to `i.ntpns.org.`, and the `.org` servers delegate `ntpns.org` to nameservers in other zones (`ns1.us.bitnames.com.`, `anyns.pch.net.` and others) without addresses. So every nameserver of `pool.ntp.org` is saved with status `error` and the reason `resolving NS a.ntpns.org.: cannot resolve a.ntpns.org.: no authoritative nameservers found`, and the name gets no records, ports or certificates. The reason is also wrong: `ntpns.org` has nameservers whose addresses were never looked up. This is `resolveARecord` in `internal/resolver/iterative.go`, which leaves its loop when the referral carries no addresses. **A referral with some addresses.** When a referral gives addresses for some of the nameservers it names, the walk to a name's nameservers asks only those and never looks up the rest. The `.org` servers' referral for `ntp.org` names four nameservers but gives an address for `ns1.everett.org.` alone, so the walk to `pool.ntp.org` depends on that one server answering. This is `followDelegation` in the same file, which looks up addresses only when the referral gives none. ## Definition of done - Both lookups follow a referral by asking every nameserver it names: those it gives addresses for, and the others once their addresses are looked up. Delegations that point at each other still end. - Watching `pool.ntp.org` shows its nameservers `a.ntpns.org.` to `i.ntpns.org.` with status `ok` and their records. - Tests against live DNS, no stand-in resolver: a nameserver name whose zone is delegated without addresses, such as `a.ntpns.org`, resolves; the walk to a name under `ntp.org` can use its nameservers that the `.org` referral gives no address for. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 07:35:28 +02:00
Author
Collaborator

Implemented in #242. Both lookups ask the nameservers whose addresses a referral gives first. When none of them answers usably, the others' addresses are looked up and those are asked. A referral with no addresses has all of them looked up, as before. Lookups stop two deep.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/dnswatcher/pulls/242. Both lookups ask the nameservers whose addresses a referral gives first. When none of them answers usably, the others' addresses are looked up and those are asked. A referral with no addresses has all of them looked up, as before. Lookups stop two deep. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#221