QueryAllNameservers took a hostname's nameservers from its last two labels.
It now passes the hostname itself to FindAuthoritativeNameservers, which
follows delegations from the root for the name and, when the name is not a zone
apex, tries each parent name in turn.
followDelegation now stops at an authoritative reply: it comes from the
servers of the zone the name is in, so it is not a referral. Before, a CNAME
answer that also listed the zone's NS records in its authority section was
followed as a referral, back to the same servers, until the delegation limit.
Not shown by the diff:
Domain targets under a suffix like co.uk had the same fault for their own
records (checkDomain calls LookupAllRecords) and are fixed too; their NS
lookup was already right.
Extra queries: an apex name costs what it did. A hostname one label below its
zone's apex takes one more walk from the root, three queries; each further
label adds another walk. Where the delegation has no glue (google.co.uk is
served by names under google.com), each walk also looks up one nameserver
address, three queries more. Querying the four nameservers of a zone already
takes about 44.
resolveNSIterative is now reached only from a non-authoritative reply that
is not a referral, such as SERVFAIL.
Disclosures:
Judgement call: the delegated-subdomain test name is a host name under compute-1.amazonaws.com, chosen for fast servers; the university and pool
zones I tried answer slower.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/dnswatcher/issues/189.
`QueryAllNameservers` took a hostname's nameservers from its last two labels.
It now passes the hostname itself to `FindAuthoritativeNameservers`, which
follows delegations from the root for the name and, when the name is not a zone
apex, tries each parent name in turn.
`followDelegation` now stops at an authoritative reply: it comes from the
servers of the zone the name is in, so it is not a referral. Before, a CNAME
answer that also listed the zone's NS records in its authority section was
followed as a referral, back to the same servers, until the delegation limit.
Not shown by the diff:
- Domain targets under a suffix like `co.uk` had the same fault for their own
records (`checkDomain` calls `LookupAllRecords`) and are fixed too; their NS
lookup was already right.
- Extra queries: an apex name costs what it did. A hostname one label below its
zone's apex takes one more walk from the root, three queries; each further
label adds another walk. Where the delegation has no glue (`google.co.uk` is
served by names under `google.com`), each walk also looks up one nameserver
address, three queries more. Querying the four nameservers of a zone already
takes about 44.
- `resolveNSIterative` is now reached only from a non-authoritative reply that
is not a referral, such as SERVFAIL.
Disclosures:
- Judgement call: the delegated-subdomain test name is a host name under
`compute-1.amazonaws.com`, chosen for fast servers; the university and pool
zones I tried answer slower.
Model: opus-5-5
A hostname's nameservers came from its last two labels, so a name under
co.uk was asked at the co.uk servers and a name in a delegated subdomain
at the parent's servers; both only refer onward. The hostname now goes
through FindAuthoritativeNameservers, which follows delegations for the
name and walks up its labels until it finds the zone it is in.
followDelegation now stops at an authoritative reply: that server holds
the zone, so its reply is not a referral. Without this, a CNAME answer
that also lists the zone's NS records in its authority section, as many
servers send, was followed as a referral until the delegation limit.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #189.
QueryAllNameserverstook a hostname's nameservers from its last two labels.It now passes the hostname itself to
FindAuthoritativeNameservers, whichfollows delegations from the root for the name and, when the name is not a zone
apex, tries each parent name in turn.
followDelegationnow stops at an authoritative reply: it comes from theservers of the zone the name is in, so it is not a referral. Before, a CNAME
answer that also listed the zone's NS records in its authority section was
followed as a referral, back to the same servers, until the delegation limit.
Not shown by the diff:
co.ukhad the same fault for their ownrecords (
checkDomaincallsLookupAllRecords) and are fixed too; their NSlookup was already right.
zone's apex takes one more walk from the root, three queries; each further
label adds another walk. Where the delegation has no glue (
google.co.ukisserved by names under
google.com), each walk also looks up one nameserveraddress, three queries more. Querying the four nameservers of a zone already
takes about 44.
resolveNSIterativeis now reached only from a non-authoritative reply thatis not a referral, such as SERVFAIL.
Disclosures:
compute-1.amazonaws.com, chosen for fast servers; the university and poolzones I tried answer slower.
Model: opus-5-5
Review passed on
e588134.Model: opus-5-5
e588134598toaec3e2fb7e