The README says: "When a referral names a zone's nameservers without their addresses, the addresses of all of them are looked up, so that each can be asked" (DNS Resolution Strategy). Two lookups do not do this.
A nameserver's own address. To ask a watched name's nameservers for its records, dnswatcher first looks up each nameserver's address, following referrals from the root servers, and gives up when a referral gives no addresses. pool.ntp.org is served by a.ntpns.org. to i.ntpns.org., and the .org servers delegate ntpns.org to nameservers in other zones (ns1.us.bitnames.com., anyns.pch.net. and others) without addresses. So every nameserver of pool.ntp.org is saved with status error and the reason resolving NS a.ntpns.org.: cannot resolve a.ntpns.org.: no authoritative nameservers found, and the name gets no records, ports or certificates. The reason is also wrong: ntpns.org has nameservers whose addresses were never looked up. This is resolveARecord in internal/resolver/iterative.go, which leaves its loop when the referral carries no addresses.
A referral with some addresses. When a referral gives addresses for some of the nameservers it names, the walk to a name's nameservers asks only those and never looks up the rest. The .org servers' referral for ntp.org names four nameservers but gives an address for ns1.everett.org. alone, so the walk to pool.ntp.org depends on that one server answering. This is followDelegation in the same file, which looks up addresses only when the referral gives none.
Definition of done
Both lookups follow a referral by asking every nameserver it names: those it gives addresses for, and the others once their addresses are looked up. Delegations that point at each other still end.
Watching pool.ntp.org shows its nameservers a.ntpns.org. to i.ntpns.org. with status ok and their records.
Tests against live DNS, no stand-in resolver: a nameserver name whose zone is delegated without addresses, such as a.ntpns.org, resolves; the walk to a name under ntp.org can use its nameservers that the .org referral gives no address for.
Model: opus-5-5
Found in the trial run for https://git.eeqj.de/sneak/dnswatcher/issues/149.
The README says: "When a referral names a zone's nameservers without their addresses, the addresses of all of them are looked up, so that each can be asked" (DNS Resolution Strategy). Two lookups do not do this.
**A nameserver's own address.** To ask a watched name's nameservers for its records, dnswatcher first looks up each nameserver's address, following referrals from the root servers, and gives up when a referral gives no addresses. `pool.ntp.org` is served by `a.ntpns.org.` to `i.ntpns.org.`, and the `.org` servers delegate `ntpns.org` to nameservers in other zones (`ns1.us.bitnames.com.`, `anyns.pch.net.` and others) without addresses. So every nameserver of `pool.ntp.org` is saved with status `error` and the reason `resolving NS a.ntpns.org.: cannot resolve a.ntpns.org.: no authoritative nameservers found`, and the name gets no records, ports or certificates. The reason is also wrong: `ntpns.org` has nameservers whose addresses were never looked up. This is `resolveARecord` in `internal/resolver/iterative.go`, which leaves its loop when the referral carries no addresses.
**A referral with some addresses.** When a referral gives addresses for some of the nameservers it names, the walk to a name's nameservers asks only those and never looks up the rest. The `.org` servers' referral for `ntp.org` names four nameservers but gives an address for `ns1.everett.org.` alone, so the walk to `pool.ntp.org` depends on that one server answering. This is `followDelegation` in the same file, which looks up addresses only when the referral gives none.
## Definition of done
- Both lookups follow a referral by asking every nameserver it names: those it gives addresses for, and the others once their addresses are looked up. Delegations that point at each other still end.
- Watching `pool.ntp.org` shows its nameservers `a.ntpns.org.` to `i.ntpns.org.` with status `ok` and their records.
- Tests against live DNS, no stand-in resolver: a nameserver name whose zone is delegated without addresses, such as `a.ntpns.org`, resolves; the walk to a name under `ntp.org` can use its nameservers that the `.org` referral gives no address for.
Model: opus-5-5
clawbot
added this to the 1.0 milestone 2026-10-02 07:35:28 +02:00
Implemented in #242. Both lookups ask the nameservers whose addresses a referral gives first. When none of them answers usably, the others' addresses are looked up and those are asked. A referral with no addresses has all of them looked up, as before. Lookups stop two deep.
Model: opus-5-5
Implemented in https://git.eeqj.de/sneak/dnswatcher/pulls/242. Both lookups ask the nameservers whose addresses a referral gives first. When none of them answers usably, the others' addresses are looked up and those are asked. A referral with no addresses has all of them looked up, as before. Lookups stop two deep.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found in the trial run for #149.
The README says: "When a referral names a zone's nameservers without their addresses, the addresses of all of them are looked up, so that each can be asked" (DNS Resolution Strategy). Two lookups do not do this.
A nameserver's own address. To ask a watched name's nameservers for its records, dnswatcher first looks up each nameserver's address, following referrals from the root servers, and gives up when a referral gives no addresses.
pool.ntp.orgis served bya.ntpns.org.toi.ntpns.org., and the.orgservers delegatentpns.orgto nameservers in other zones (ns1.us.bitnames.com.,anyns.pch.net.and others) without addresses. So every nameserver ofpool.ntp.orgis saved with statuserrorand the reasonresolving NS a.ntpns.org.: cannot resolve a.ntpns.org.: no authoritative nameservers found, and the name gets no records, ports or certificates. The reason is also wrong:ntpns.orghas nameservers whose addresses were never looked up. This isresolveARecordininternal/resolver/iterative.go, which leaves its loop when the referral carries no addresses.A referral with some addresses. When a referral gives addresses for some of the nameservers it names, the walk to a name's nameservers asks only those and never looks up the rest. The
.orgservers' referral forntp.orgnames four nameservers but gives an address forns1.everett.org.alone, so the walk topool.ntp.orgdepends on that one server answering. This isfollowDelegationin the same file, which looks up addresses only when the referral gives none.Definition of done
pool.ntp.orgshows its nameserversa.ntpns.org.toi.ntpns.org.with statusokand their records.a.ntpns.org, resolves; the walk to a name underntp.orgcan use its nameservers that the.orgreferral gives no address for.Model: opus-5-5
Implemented in #242. Both lookups ask the nameservers whose addresses a referral gives first. When none of them answers usably, the others' addresses are looked up and those are asked. A referral with no addresses has all of them looked up, as before. Lookups stop two deep.
Model: opus-5-5