feat: complete Phase 4.1 error handling and robustness (HAN-385)
CI / test (pull_request) Failing after 2m41s

- Fast mode cache isolation: TraverserConfig.Fast=false gives each
  referral its own independent InfoCache with no cross-branch glue
  inheritance; Fast=true (default) retains the shared root cache so
  earlier branch discoveries are reused
- Wire cfg.Fast from CLI config into TraverserConfig in main.go
- IDN/Punycode: NewReferral now converts unicode domain labels to their
  ACE/punycode form via golang.org/x/net/idna before querying, with a
  graceful fallback when conversion fails
- DNSSEC: hasFinalAnswer() now skips RRSIG records alongside CNAME so
  a signed referral does not prevent CNAME following
- Tests: DNSSEC RRSIG does not block CNAME follow, fast/non-fast cache
  isolation, 12-NS referral, IDN conversion, wildcard answer, long CNAME
  chain depth limit, partial branch failure with graceful degradation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: multica-agent <github@multica.ai>
This commit is contained in:
Gary Hansen
2026-06-08 03:22:21 +10:00
co-authored by Copilot multica-agent
parent 368f200d23
commit 6e9aefc47e
7 changed files with 451 additions and 11 deletions
+20 -3
View File
@@ -18,6 +18,12 @@ type TraverserConfig struct {
QueryConfig *dns.QueryConfig
RootAddrs []net.IP
Hooks *TraverserHooks
// Fast controls cache sharing across branches. When true (default), child
// branches inherit glue discovered by earlier branches via the shared root
// cache, trading accuracy for speed. When false, each branch gets a
// completely independent cache — slower but results are not contaminated by
// sibling branch observations.
Fast bool
}
func DefaultTraverserConfig() *TraverserConfig {
@@ -27,6 +33,7 @@ func DefaultTraverserConfig() *TraverserConfig {
RootConfig: nil,
QueryConfig: nil,
RootAddrs: nil,
Fast: true,
}
}
@@ -98,9 +105,19 @@ func (t *Traverser) Traverse(ctx context.Context, name string) ([]TraversalResul
break
}
cache := rootCache
if ref.Parent != nil {
cache = rootCache.Child()
var cache *InfoCache
if t.config.Fast {
// Fast mode: inherit glue from the shared root cache so earlier
// branch discoveries are visible to later branches.
cache = rootCache
if ref.Parent != nil {
cache = rootCache.Child()
}
} else {
// Non-fast mode: every referral gets its own independent cache so
// no cross-branch glue is reused, ensuring each path is resolved
// from scratch.
cache = NewInfoCache(nil)
}
if t.config.Hooks != nil {