resolver: pass over a server that answers SERVFAIL or refers no closer (closes #197) #201

Merged
clawbot merged 1 commits from issue-197-zone-search-next-server into next 2026-10-02 01:17:39 +02:00
Collaborator

Finding a zone's servers walks from the root servers towards the name, asking one server at a time. A timeout or a refusal already moved on to the zone's next server, but a SERVFAIL or a referral was taken as the zone's reply. One bad server then made the search give up on the zone, or follow a referral that led nowhere until the step limit.

Now a reply is used only when it is an answer, NXDOMAIN, or a referral to a zone below the zone of the servers asked that the name is in. Any other reply passes on to the zone's next server, and the zone is given up only when none of its servers gave a usable reply. To judge referrals, each walk keeps the zone of the servers it is asking: . at the root servers, then the zone named by each referral it follows.

queryServers takes the new zone argument. The work for #138 changes the same function and will meet it when it rebases; the order servers are tried in is untouched here.

  • Judgement call: other error replies, such as FORMERR, are passed over like SERVFAIL.
  • Judgement call: the search for a nameserver's address and the fallback search for a zone's NS records share the server loop, so they change too.
  • Partly verified: the decision is tested on replies built in the test; no live test, as no zone is known to keep one bad server.

Model: opus-5-5

Finding a zone's servers walks from the root servers towards the name, asking one server at a time. A timeout or a refusal already moved on to the zone's next server, but a SERVFAIL or a referral was taken as the zone's reply. One bad server then made the search give up on the zone, or follow a referral that led nowhere until the step limit. Now a reply is used only when it is an answer, NXDOMAIN, or a referral to a zone below the zone of the servers asked that the name is in. Any other reply passes on to the zone's next server, and the zone is given up only when none of its servers gave a usable reply. To judge referrals, each walk keeps the zone of the servers it is asking: `.` at the root servers, then the zone named by each referral it follows. `queryServers` takes the new `zone` argument. The work for https://git.eeqj.de/sneak/dnswatcher/issues/138 changes the same function and will meet it when it rebases; the order servers are tried in is untouched here. - Judgement call: other error replies, such as FORMERR, are passed over like SERVFAIL. - Judgement call: the search for a nameserver's address and the fallback search for a zone's NS records share the server loop, so they change too. - Partly verified: the decision is tested on replies built in the test; no live test, as no zone is known to keep one bad server. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 00:46:44 +02:00
clawbot self-assigned this 2026-10-02 00:46:44 +02:00
clawbot added 1 commit 2026-10-02 00:46:45 +02:00
When the resolver walks from the root servers towards a name, a server
that answered SERVFAIL, or referred the query back to its own zone, up
or sideways, ended the step, so finding a zone's servers gave up on the
zone though its other servers would answer. Such a reply is now passed
over for the zone's next server, as a timeout or a refusal already was.
To tell a referral that leads closer to the name from one that does
not, each walk keeps the zone of the servers it is asking. Other error
replies, such as FORMERR, are passed over too. The walk that finds a
nameserver's address shares the same server loop, so it changes too.

Model: opus-5-5
Author
Collaborator

Review passed on b3aab92.

Model: opus-5-5

Review passed on b3aab92. Model: opus-5-5
clawbot merged commit d09822562d into next 2026-10-02 01:17:39 +02:00
clawbot deleted branch issue-197-zone-search-next-server 2026-10-02 01:17:40 +02:00
clawbot removed the needs-review label 2026-10-02 01:17:41 +02:00
Sign in to join this conversation.