From 3da28da9a260e80a7923308b5b7ad747052aa6e8 Mon Sep 17 00:00:00 2001 From: Gary Hansen Date: Mon, 8 Jun 2026 18:07:38 +1000 Subject: [PATCH] Fix NS resolution, deduplicate results, fix FormatRecord duplication Three bugs fixed: 1. processReferral was calling ResolveNS with ref.Name (the query domain, e.g. '800adventures.com.au.') instead of ref.Bailiwick (the NS hostname, e.g. 'ns-a.hansenits.com.'). This caused the sub-traversal to look up the wrong name and always fail to find the nameserver's IP address. 2. In ResolveNS (and Referral.Resolve), child referrals whose name matched the visited set were unconditionally skipped. When the .com TLD returns glue A records for the target NS alongside its delegation, the child referral has addresses and should be queried directly rather than skipped. 3. FormatRecord was prepending the DNS header fields and then appending rr.String() which already includes those same fields, producing doubled output like 'example.com. 300 IN A example.com. 300 IN A 1.2.3.4'. Now simply returns rr.String(). Additional improvements: - Results section deduplicates terminal results: same NS failure or same (NS, answer) pair is merged with summed probability, avoiding the same nameserver appearing 15 times with 6.7% each. - Result lines now include the NS hostname (from Bailiwick) and use the compact rdata format, e.g. '33% ns-a.hansenits.com answered with 13.54.63.231'. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: multica-agent --- internal/dns/decode.go | 10 +------ internal/output/stats.go | 51 ++++++++++++++++++++++++++++++++++ internal/output/text.go | 12 ++++---- internal/traverse/referral.go | 5 +++- internal/traverse/traverser.go | 21 +++++++++----- 5 files changed, 77 insertions(+), 22 deletions(-) diff --git a/internal/dns/decode.go b/internal/dns/decode.go index 3e868f1..5a9d605 100644 --- a/internal/dns/decode.go +++ b/internal/dns/decode.go @@ -1,7 +1,6 @@ package dns import ( - "fmt" "strings" "github.com/miekg/dns" @@ -234,12 +233,5 @@ func FormatRecord(rr dns.RR) string { if rr == nil { return "" } - header := rr.Header() - return fmt.Sprintf("%s %d %s %s %s", - header.Name, - header.Ttl, - dns.ClassToString[header.Class], - QNameType(header.Rrtype), - rr.String(), - ) + return rr.String() } diff --git a/internal/output/stats.go b/internal/output/stats.go index b7c1aa2..48109dd 100644 --- a/internal/output/stats.go +++ b/internal/output/stats.go @@ -196,3 +196,54 @@ func containsString(items []string, target string) bool { } return false } + +// DeduplicateResults collapses terminal results that represent the same +// outcome from the same server into a single entry with summed probability. +// This prevents the same nameserver failure (or answer) from appearing once +// per delegation path when several parent servers all refer to the same child. +func DeduplicateResults(results []traverse.TraversalResult) []traverse.TraversalResult { + type entry struct { + result traverse.TraversalResult + prob float64 + } + keys := make(map[string]*entry) + var order []string + + for _, r := range results { + if r.Response == nil || r.Referral == nil { + continue + } + key := resultDeduplicationKey(r) + if e, ok := keys[key]; ok { + e.prob += r.Referral.Prob + } else { + keys[key] = &entry{result: r, prob: r.Referral.Prob} + order = append(order, key) + } + } + + deduped := make([]traverse.TraversalResult, 0, len(order)) + for _, key := range order { + e := keys[key] + refCopy := *e.result.Referral + refCopy.Prob = e.prob + deduped = append(deduped, traverse.TraversalResult{ + Referral: &refCopy, + Response: e.result.Response, + }) + } + return deduped +} + +func resultDeduplicationKey(r traverse.TraversalResult) string { + bailiwick := strings.TrimSuffix(r.Referral.Bailiwick, ".") + switch r.Response.Type { + case traverse.RespAnswer: + key, _ := answerKey(r.Response) + return "answer:" + bailiwick + ":" + key + case traverse.RespNSResolutionFailed: + return "ns_error:" + r.Response.ErrorMessage + default: + return r.Response.Type.String() + ":" + bailiwick + ":" + r.Response.ErrorMessage + } +} diff --git a/internal/output/text.go b/internal/output/text.go index 53b657a..4891a21 100644 --- a/internal/output/text.go +++ b/internal/output/text.go @@ -120,7 +120,8 @@ func (f *textFormatter) writeResults(results []traverse.TraversalResult) error { } terminal := terminalResults(results) - for _, result := range terminal { + deduped := DeduplicateResults(terminal) + for _, result := range deduped { prefix := strings.Repeat(" ", result.Referral.Depth+1) line := prefix + f.formatResultLine(result) if _, err := fmt.Fprintln(f.w, line); err != nil { @@ -196,14 +197,15 @@ func (f *textFormatter) formatResultLine(result traverse.TraversalResult) string prob := formatProbability(result.Referral.Prob) switch result.Response.Type { case traverse.RespAnswer: - key, rrs := answerKey(result.Response) + key, _ := answerKey(result.Response) if key == "" { return fmt.Sprintf("%s resulted in answer", prob) } - if len(rrs) == 1 { - return f.colorize(fmt.Sprintf("%s answered with %s", prob, rrs[0]), colorGreen) + nsLabel := "" + if result.Referral.Bailiwick != "" && result.Referral.Bailiwick != "." { + nsLabel = trimDomain(result.Referral.Bailiwick) + " " } - return f.colorize(fmt.Sprintf("%s answered with %s", prob, strings.Join(rrs, " / ")), colorGreen) + return f.colorize(fmt.Sprintf("%s %sanswered with %s", prob, nsLabel, key), colorGreen) case traverse.RespNODATA: return fmt.Sprintf("%s found no such record", prob) case traverse.RespNXDOMAIN: diff --git a/internal/traverse/referral.go b/internal/traverse/referral.go index ca78481..c5a0917 100644 --- a/internal/traverse/referral.go +++ b/internal/traverse/referral.go @@ -230,7 +230,10 @@ func (r *Referral) Resolve(ctx context.Context, traverser *Traverser, cache *Inf if resp.Type == RespReferral { children := resp.ChildReferrals() for _, child := range children { - if visited != nil && visited[child.Name] { + // Only skip visited names when they have no addresses; if glue + // was included in the referral response we still need to query + // that child to get the authoritative answer. + if visited != nil && visited[child.Name] && !child.HasAddresses() { continue } if !stack.Push(child) { diff --git a/internal/traverse/traverser.go b/internal/traverse/traverser.go index e139db1..185c2d1 100644 --- a/internal/traverse/traverser.go +++ b/internal/traverse/traverser.go @@ -227,15 +227,19 @@ func (t *Traverser) processReferral(ctx context.Context, ref *Referral, cache *I } t.mu.Unlock() - ref.Addresses = t.resolveGlueViaSystem(ctx, ref.Name, cache) + // Resolve the nameserver's IP address. The NS hostname is stored in + // Bailiwick; ref.Name is the domain being queried (not the NS name). + nsToResolve := ref.Bailiwick + if nsToResolve == "" || nsToResolve == "." { + nsToResolve = ref.Name + } + nsName := strings.TrimSuffix(nsToResolve, ".") + + ref.Addresses = t.resolveGlueViaSystem(ctx, nsToResolve, cache) if len(ref.Addresses) > 0 { ref.State = StateResolved } else { - addrs, err := t.ResolveNS(ctx, ref.Name, cache, visitedCopy, t.depth) - nsName := strings.TrimSuffix(ref.Bailiwick, ".") - if nsName == "" || nsName == "." { - nsName = strings.TrimSuffix(ref.Name, ".") - } + addrs, err := t.ResolveNS(ctx, nsToResolve, cache, visitedCopy, t.depth) if err != nil { return &Response{ Referral: ref, @@ -375,7 +379,10 @@ func (t *Traverser) ResolveNS(ctx context.Context, nsName string, cache *InfoCac if resp.Type == RespReferral { children := resp.ChildReferrals() for _, child := range children { - if visited != nil && visited[child.Name] { + // Only skip visited names when they have no addresses; if glue + // was included in the referral response we still need to query + // that child to get the authoritative answer. + if visited != nil && visited[child.Name] && !child.HasAddresses() { continue } if !stack.Push(child) {