A domain's NS set (LookupNS, FindAuthoritativeNameservers) is now its delegation: the NS records in the referral its parent zone's servers send for it, which they all hold alike. The walk from the root servers stops at that referral, and the domain's own servers are no longer asked for their NS records. Before, the set came from whichever of them answered first, so when they disagreed (a move between DNS providers, a stale secondary) it could differ between checks and send an NS change notification each time. The README already describes the domain check as watching nameservers added to or removed from the delegation.
Not visible in the diff:
Hostnames go through the same function, so the servers of the zone a hostname is in are now that zone's delegation too.
When all of a domain's own servers fail, the set stays the delegation. Before, the lookup moved on to the parent name and returned the parent zone's servers (such as the com servers) as the domain's NS set.
A server that holds both the parent zone and the domain gives no referral; its answer with the domain's own NS records is still used.
Disclosures:
Partially verified: the test runs the deciding step on replies built in the test; that every server of a parent zone sends the same delegation is assumed, not tested.
Judgement call: a nameserver listed only in the domain's own NS records, not in the delegation, is no longer queried.
Model: opus-5-5
A domain's NS set (`LookupNS`, `FindAuthoritativeNameservers`) is now its delegation: the NS records in the referral its parent zone's servers send for it, which they all hold alike. The walk from the root servers stops at that referral, and the domain's own servers are no longer asked for their NS records. Before, the set came from whichever of them answered first, so when they disagreed (a move between DNS providers, a stale secondary) it could differ between checks and send an NS change notification each time. The README already describes the domain check as watching nameservers added to or removed from the delegation.
Not visible in the diff:
- Hostnames go through the same function, so the servers of the zone a hostname is in are now that zone's delegation too.
- When all of a domain's own servers fail, the set stays the delegation. Before, the lookup moved on to the parent name and returned the parent zone's servers (such as the `com` servers) as the domain's NS set.
- A server that holds both the parent zone and the domain gives no referral; its answer with the domain's own NS records is still used.
Disclosures:
- Partially verified: the test runs the deciding step on replies built in the test; that every server of a parent zone sends the same delegation is assumed, not tested.
- Judgement call: a nameserver listed only in the domain's own NS records, not in the delegation, is no longer queried.
Model: opus-5-5
A domain's NS set was taken from whichever of its own servers answered
first, so when they disagree (during a move between DNS providers, or
with a stale secondary) the set could change between checks and send an
NS change notification with nothing changed. The walk now stops at the
referral to the domain from its parent zone's servers and returns that
delegation, which those servers all hold alike; the domain's own
servers are no longer asked for it. The NS records in an answer are
still used where no such referral comes first, as from a server that
holds both the parent zone and the domain. Hostnames get their zone's
servers the same way.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
A domain's NS set (
LookupNS,FindAuthoritativeNameservers) is now its delegation: the NS records in the referral its parent zone's servers send for it, which they all hold alike. The walk from the root servers stops at that referral, and the domain's own servers are no longer asked for their NS records. Before, the set came from whichever of them answered first, so when they disagreed (a move between DNS providers, a stale secondary) it could differ between checks and send an NS change notification each time. The README already describes the domain check as watching nameservers added to or removed from the delegation.Not visible in the diff:
comservers) as the domain's NS set.Disclosures:
Model: opus-5-5
Review passed on
6bd6669.Model: opus-5-5