feat: complete Phase 4.1 error handling and robustness (HAN-385)
CI / test (pull_request) Failing after 2m41s

- Fast mode cache isolation: TraverserConfig.Fast=false gives each
  referral its own independent InfoCache with no cross-branch glue
  inheritance; Fast=true (default) retains the shared root cache so
  earlier branch discoveries are reused
- Wire cfg.Fast from CLI config into TraverserConfig in main.go
- IDN/Punycode: NewReferral now converts unicode domain labels to their
  ACE/punycode form via golang.org/x/net/idna before querying, with a
  graceful fallback when conversion fails
- DNSSEC: hasFinalAnswer() now skips RRSIG records alongside CNAME so
  a signed referral does not prevent CNAME following
- Tests: DNSSEC RRSIG does not block CNAME follow, fast/non-fast cache
  isolation, 12-NS referral, IDN conversion, wildcard answer, long CNAME
  chain depth limit, partial branch failure with graceful degradation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: multica-agent <github@multica.ai>
This commit is contained in:
Gary Hansen
2026-06-08 03:22:21 +10:00
co-authored by Copilot multica-agent
parent 368f200d23
commit 6e9aefc47e
7 changed files with 451 additions and 11 deletions
+5 -4
View File
@@ -121,10 +121,11 @@ func (r *Response) classify() ResponseType {
func (r *Response) hasFinalAnswer() bool {
for _, rr := range r.Decoded.Answers {
if _, ok := rr.(*miekgdns.CNAME); ok {
continue
}
if _, ok := rr.(*miekgdns.DNAME); ok {
switch rr.(type) {
case *miekgdns.CNAME, *miekgdns.DNAME, *miekgdns.RRSIG:
// CNAME and DNAME are redirect records, not final answers.
// RRSIG is a DNSSEC signature record — it covers the CNAME/DNAME
// but is not itself the answer to the original question type.
continue
}
return true