Red next: the Quad9 refusal test needs all eight of its queries answered at once #251

Closed
opened 2026-10-02 11:25:27 +02:00 by clawbot · 2 comments
Collaborator

Top priority: next is red because of this. At 6332b48, script/cibuild failed in make test: this test timed out on every query to both Quad9 addresses in all three attempts (63.7s), then passed on the rerun; the step still fails.

TestQueryNameserverIP_RecursiveResolverRefused in internal/resolver/resolver_test.go (added for #206) asks Quad9 for every record type a nameserver query covers, eight queries, and passes only when all eight get a reply within one attempt. With 5% of outgoing packets dropped in a test container, it ran into the suite's 90-second backstop several times while timing #250, on that branch and once on a tree with only part of that change. It has not failed on next in nine such runs, but it fails whenever Quad9 goes quiet for a few seconds, so it can turn CI red the way #214 did.

Definition of done:

  • The test sends only the queries it needs to show that a refused query is not resent asking for recursion, and retries through internal/livednstest, as the other live resolver tests do. Quad9 went silent on both its addresses for a whole minute in the red run, so the test must not depend on one operator: it can use any public resolver that refuses a query not asking for recursion, trying several before it gives up.
  • It still fails if the resend asking for recursion comes back (put it back by hand and confirm).
  • DNS is never mocked: no stand-in resolver, no skipped test, nothing taken out of the default run, no longer time limit.
  • With 5% of outgoing packets dropped, eight runs of the suite pass, and internal/resolver takes no longer than on next.

Model: opus-5-5

**Top priority: `next` is red because of this.** At `6332b48`, `script/cibuild` failed in `make test`: this test timed out on every query to both Quad9 addresses in all three attempts (63.7s), then passed on the rerun; the step still fails. `TestQueryNameserverIP_RecursiveResolverRefused` in `internal/resolver/resolver_test.go` (added for https://git.eeqj.de/sneak/dnswatcher/issues/206) asks Quad9 for every record type a nameserver query covers, eight queries, and passes only when all eight get a reply within one attempt. With 5% of outgoing packets dropped in a test container, it ran into the suite's 90-second backstop several times while timing https://git.eeqj.de/sneak/dnswatcher/pulls/250, on that branch and once on a tree with only part of that change. It has not failed on `next` in nine such runs, but it fails whenever Quad9 goes quiet for a few seconds, so it can turn CI red the way https://git.eeqj.de/sneak/dnswatcher/issues/214 did. Definition of done: - The test sends only the queries it needs to show that a refused query is not resent asking for recursion, and retries through `internal/livednstest`, as the other live resolver tests do. Quad9 went silent on both its addresses for a whole minute in the red run, so the test must not depend on one operator: it can use any public resolver that refuses a query not asking for recursion, trying several before it gives up. - It still fails if the resend asking for recursion comes back (put it back by hand and confirm). - DNS is never mocked: no stand-in resolver, no skipped test, nothing taken out of the default run, no longer time limit. - With 5% of outgoing packets dropped, eight runs of the suite pass, and `internal/resolver` takes no longer than on `next`. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 11:25:27 +02:00
clawbot self-assigned this 2026-10-02 11:25:27 +02:00
clawbot changed title from The Quad9 refusal test needs all eight of its queries answered at once, so packet loss fails it to Red next: the Quad9 refusal test needs all eight of its queries answered at once 2026-10-02 11:27:33 +02:00
Author
Collaborator

It has since failed this way on next itself at 9b9e26d, with 5% of outgoing packets dropped, so it is not specific to #250.

Model: opus-5-5

It has since failed this way on `next` itself at `9b9e26d`, with 5% of outgoing packets dropped, so it is not specific to https://git.eeqj.de/sneak/dnswatcher/pulls/250. Model: opus-5-5
Author
Collaborator

#252 replaces the test with TestQueryServers_RecursiveResolverRefused: it sends one A query to public resolvers of four operators in turn, stops at the first that replies, and is retried through internal/livednstest. How the four were chosen is in the PR body.

Model: opus-5-5

https://git.eeqj.de/sneak/dnswatcher/pulls/252 replaces the test with `TestQueryServers_RecursiveResolverRefused`: it sends one A query to public resolvers of four operators in turn, stops at the first that replies, and is retried through `internal/livednstest`. How the four were chosen is in the PR body. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#251