check / check (push) Failing after 2m28s
queryDNS resent a query that a server refused, this time asking for recursion, so on a network that intercepts DNS the answers could come from a recursive resolver without anyone knowing. A refusal is now only a refusal, and the server is passed over for the next. When every server of a zone refuses, the error says so. When every root server refuses, the error is ErrIntercepted: root servers refuse no query, so something on the network is answering in their place. FindAuthoritativeNameservers stops at that error instead of trying each parent name, so the watcher's log line says it. A live test asks Quad9, which refuses a query not asking for recursion, so that the resend cannot come back unnoticed. Model: opus-5-5
71 lines
1.6 KiB
Go
71 lines
1.6 KiB
Go
package resolver
|
|
|
|
import (
|
|
"context"
|
|
|
|
"github.com/miekg/dns"
|
|
)
|
|
|
|
// ExtractRecordValue exports extractRecordValue for testing.
|
|
func ExtractRecordValue(rr dns.RR) string {
|
|
return extractRecordValue(rr)
|
|
}
|
|
|
|
// UsableReply exports usableReply for testing.
|
|
func UsableReply(resp *dns.Msg, zone string, name string) bool {
|
|
return usableReply(resp, zone, name)
|
|
}
|
|
|
|
// NSSetFrom exports nsSetFrom for testing.
|
|
func NSSetFrom(resp *dns.Msg, domain string) []string {
|
|
return nsSetFrom(resp, domain)
|
|
}
|
|
|
|
// CollectIPs exports collectIPs for testing.
|
|
func CollectIPs(
|
|
results map[string]*NameserverResponse,
|
|
) ([]string, string, error) {
|
|
return collectIPs(results)
|
|
}
|
|
|
|
// QueryServers exports queryServers for testing.
|
|
func (r *Resolver) QueryServers(
|
|
ctx context.Context,
|
|
servers []string,
|
|
zone string,
|
|
name string,
|
|
qtype uint16,
|
|
) (*dns.Msg, error) {
|
|
return r.queryServers(ctx, servers, zone, name, qtype)
|
|
}
|
|
|
|
// QueryEachNS exports queryEachNS for testing.
|
|
func (r *Resolver) QueryEachNS(
|
|
ctx context.Context,
|
|
nameservers []string,
|
|
hostname string,
|
|
) (map[string]*NameserverResponse, error) {
|
|
return r.queryEachNS(ctx, nameservers, hostname)
|
|
}
|
|
|
|
// ResolveNSIPs exports resolveNSIPs for testing.
|
|
func (r *Resolver) ResolveNSIPs(
|
|
ctx context.Context,
|
|
nsNames []string,
|
|
) []string {
|
|
return r.resolveNSIPs(ctx, nsNames)
|
|
}
|
|
|
|
// RootServerList exports rootServerList for testing.
|
|
func RootServerList() []string {
|
|
return rootServerList()
|
|
}
|
|
|
|
// Shuffled exports shuffled for testing.
|
|
func Shuffled(
|
|
servers []string,
|
|
shuffle func(n int, swap func(i, j int)),
|
|
) []string {
|
|
return shuffled(servers, shuffle)
|
|
}
|