agent-substrate / agent-substrate/substrate

atenet/dns: actor zone returns NXDOMAIN for empty non-terminals

未關閉
#922 0 則留言 0 個 reaction 已指派 1 人 已被 @ygao-g 認領 在 GitHub 檢視
area/network kind/bug
主要語言
Go
星號
1.8k
分支
316
平均合併
2 天 43 分鐘
30 天內合併 PR
287

描述

The terminal NXDOMAIN catch-all added in #874 also answers NXDOMAIN for the zone apex, `actors.resources.substrate.ate.dev`, and for `.actors.resources.substrate.ate.dev`. Neither is an absent name: the apex exists by definition, and the zone answers for any well-formed `.` pair, so every `` label has children. Both are empty non-terminals, and the correct answer for one is NOERROR with an empty answer section, not NXDOMAIN.

NXDOMAIN asserts something stronger -- RFC 8020, "NXDOMAIN really means there's nothing below" -- so a resolver that caches it for `` may decline to resolve any actor in that atespace. That is a hard resolution outage rather than a degradation, which is why it is worth tracking even though nothing hits it today.

Latent for now: it needs a resolver in front that both queries the intermediate name (QNAME minimisation, RFC 7816) and applies NXDOMAIN cuts. kube-dns `stubDomains` and the CoreDNS `forward` plugin pass the full qname through, the CoreDNS `cache` plugin caches per (qname, qtype) without aggressive negative caching, and musl and glibc do not cache at all.

The fix is one more `template` block before the catch-all, scoped by a `match` carrying the apex and single-label patterns, with `rcode NOERROR`, the same SOA authority record, and `fallthrough`. Ordering is load-bearing: after the actor NODATA block, before the catch-all. Worth deciding first whether an apex `SOA` or `NS` query should be answered properly instead, in which case `file`/`auto` with a real zone is a better shape than a fourth `template` block.

Reproduced against `coredns/coredns:1.11.1`, the pinned image: `A ns1.actors.resources.substrate.ate.dev` and `SOA actors.resources.substrate.ate.dev` both return NXDOMAIN. `corefile.go` carries a TODO pointing here. Follow-up to #874.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。