resolver: query a hostname at its own zone's servers (closes #189) #191

Merged
clawbot merged 1 commits from issue-189-hostname-zone into next 2026-10-01 23:34:36 +02:00
Collaborator

Closes #189.

QueryAllNameservers took a hostname's nameservers from its last two labels.
It now passes the hostname itself to FindAuthoritativeNameservers, which
follows delegations from the root for the name and, when the name is not a zone
apex, tries each parent name in turn.

followDelegation now stops at an authoritative reply: it comes from the
servers of the zone the name is in, so it is not a referral. Before, a CNAME
answer that also listed the zone's NS records in its authority section was
followed as a referral, back to the same servers, until the delegation limit.

Not shown by the diff:

  • Domain targets under a suffix like co.uk had the same fault for their own
    records (checkDomain calls LookupAllRecords) and are fixed too; their NS
    lookup was already right.
  • Extra queries: an apex name costs what it did. A hostname one label below its
    zone's apex takes one more walk from the root, three queries; each further
    label adds another walk. Where the delegation has no glue (google.co.uk is
    served by names under google.com), each walk also looks up one nameserver
    address, three queries more. Querying the four nameservers of a zone already
    takes about 44.
  • resolveNSIterative is now reached only from a non-authoritative reply that
    is not a referral, such as SERVFAIL.

Disclosures:

  • Judgement call: the delegated-subdomain test name is a host name under
    compute-1.amazonaws.com, chosen for fast servers; the university and pool
    zones I tried answer slower.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/dnswatcher/issues/189. `QueryAllNameservers` took a hostname's nameservers from its last two labels. It now passes the hostname itself to `FindAuthoritativeNameservers`, which follows delegations from the root for the name and, when the name is not a zone apex, tries each parent name in turn. `followDelegation` now stops at an authoritative reply: it comes from the servers of the zone the name is in, so it is not a referral. Before, a CNAME answer that also listed the zone's NS records in its authority section was followed as a referral, back to the same servers, until the delegation limit. Not shown by the diff: - Domain targets under a suffix like `co.uk` had the same fault for their own records (`checkDomain` calls `LookupAllRecords`) and are fixed too; their NS lookup was already right. - Extra queries: an apex name costs what it did. A hostname one label below its zone's apex takes one more walk from the root, three queries; each further label adds another walk. Where the delegation has no glue (`google.co.uk` is served by names under `google.com`), each walk also looks up one nameserver address, three queries more. Querying the four nameservers of a zone already takes about 44. - `resolveNSIterative` is now reached only from a non-authoritative reply that is not a referral, such as SERVFAIL. Disclosures: - Judgement call: the delegated-subdomain test name is a host name under `compute-1.amazonaws.com`, chosen for fast servers; the university and pool zones I tried answer slower. Model: opus-5-5
clawbot added the needs-review label 2026-10-01 23:16:26 +02:00
clawbot self-assigned this 2026-10-01 23:16:26 +02:00
Author
Collaborator

Review passed on e588134.

Model: opus-5-5

Review passed on e588134. Model: opus-5-5
clawbot added 1 commit 2026-10-01 23:33:55 +02:00
A hostname's nameservers came from its last two labels, so a name under
co.uk was asked at the co.uk servers and a name in a delegated subdomain
at the parent's servers; both only refer onward. The hostname now goes
through FindAuthoritativeNameservers, which follows delegations for the
name and walks up its labels until it finds the zone it is in.

followDelegation now stops at an authoritative reply: that server holds
the zone, so its reply is not a referral. Without this, a CNAME answer
that also lists the zone's NS records in its authority section, as many
servers send, was followed as a referral until the delegation limit.

Model: opus-5-5
clawbot force-pushed issue-189-hostname-zone from e588134598 to aec3e2fb7e 2026-10-01 23:33:55 +02:00 Compare
clawbot merged commit 797c936c48 into next 2026-10-01 23:34:36 +02:00
clawbot deleted branch issue-189-hostname-zone 2026-10-01 23:34:36 +02:00
clawbot removed the needs-review label 2026-10-01 23:34:36 +02:00
Sign in to join this conversation.