CI / test (pull_request) Failing after 2m31s
Three bugs fixed: 1. processReferral was calling ResolveNS with ref.Name (the query domain, e.g. '800adventures.com.au.') instead of ref.Bailiwick (the NS hostname, e.g. 'ns-a.hansenits.com.'). This caused the sub-traversal to look up the wrong name and always fail to find the nameserver's IP address. 2. In ResolveNS (and Referral.Resolve), child referrals whose name matched the visited set were unconditionally skipped. When the .com TLD returns glue A records for the target NS alongside its delegation, the child referral has addresses and should be queried directly rather than skipped. 3. FormatRecord was prepending the DNS header fields and then appending rr.String() which already includes those same fields, producing doubled output like 'example.com. 300 IN A example.com. 300 IN A 1.2.3.4'. Now simply returns rr.String(). Additional improvements: - Results section deduplicates terminal results: same NS failure or same (NS, answer) pair is merged with summed probability, avoiding the same nameserver appearing 15 times with 6.7% each. - Result lines now include the NS hostname (from Bailiwick) and use the compact rdata format, e.g. '33% ns-a.hansenits.com answered with 13.54.63.231'. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: multica-agent <github@multica.ai>
238 lines
4.7 KiB
Go
238 lines
4.7 KiB
Go
package dns
|
|
|
|
import (
|
|
"strings"
|
|
|
|
"github.com/miekg/dns"
|
|
)
|
|
|
|
type ResponseClassification int
|
|
|
|
const (
|
|
ResponseAnswer ResponseClassification = iota
|
|
ResponseReferral
|
|
ResponseNODATA
|
|
ResponseNXDOMAIN
|
|
ResponseSERVFAIL
|
|
ResponseREFUSED
|
|
ResponseNOTIMPL
|
|
ResponseOther
|
|
)
|
|
|
|
func (rc ResponseClassification) String() string {
|
|
switch rc {
|
|
case ResponseAnswer:
|
|
return "answer"
|
|
case ResponseReferral:
|
|
return "referral"
|
|
case ResponseNODATA:
|
|
return "nodata"
|
|
case ResponseNXDOMAIN:
|
|
return "nxdomain"
|
|
case ResponseSERVFAIL:
|
|
return "servfail"
|
|
case ResponseREFUSED:
|
|
return "refused"
|
|
case ResponseNOTIMPL:
|
|
return "notimp"
|
|
default:
|
|
return "other"
|
|
}
|
|
}
|
|
|
|
type DecodedResponse struct {
|
|
Rcode int
|
|
RcodeName string
|
|
Truncated bool
|
|
RecursionAvailable bool
|
|
Authoritative bool
|
|
Classification ResponseClassification
|
|
Answers []dns.RR
|
|
Authority []dns.RR
|
|
Additional []dns.RR
|
|
CNAMEChain []string
|
|
DNAMEMappings []DNAMEMapping
|
|
}
|
|
|
|
// DNAMEMapping holds a DNAME record's owner and target for redirect synthesis.
|
|
type DNAMEMapping struct {
|
|
Owner string // e.g., "example.com."
|
|
Target string // e.g., "example.net."
|
|
}
|
|
|
|
func DecodeResponse(msg *dns.Msg) *DecodedResponse {
|
|
if msg == nil {
|
|
return nil
|
|
}
|
|
|
|
d := &DecodedResponse{
|
|
Rcode: msg.Rcode,
|
|
RcodeName: dns.RcodeToString[msg.Rcode],
|
|
Truncated: msg.Truncated,
|
|
RecursionAvailable: msg.RecursionAvailable,
|
|
Authoritative: msg.Authoritative,
|
|
Answers: msg.Answer,
|
|
Authority: msg.Ns,
|
|
Additional: msg.Extra,
|
|
CNAMEChain: extractCNAMEChain(msg),
|
|
DNAMEMappings: extractDNAMEMappings(msg),
|
|
}
|
|
|
|
d.Classification = classify(msg)
|
|
|
|
return d
|
|
}
|
|
|
|
func classify(msg *dns.Msg) ResponseClassification {
|
|
switch msg.Rcode {
|
|
case dns.RcodeNameError:
|
|
return ResponseNXDOMAIN
|
|
case dns.RcodeServerFailure:
|
|
return ResponseSERVFAIL
|
|
case dns.RcodeRefused:
|
|
return ResponseREFUSED
|
|
case dns.RcodeNotImplemented:
|
|
return ResponseNOTIMPL
|
|
case dns.RcodeSuccess:
|
|
return classifySuccess(msg)
|
|
default:
|
|
return ResponseOther
|
|
}
|
|
}
|
|
|
|
func classifySuccess(msg *dns.Msg) ResponseClassification {
|
|
hasAnswers := len(msg.Answer) > 0
|
|
|
|
if hasAnswers {
|
|
return ResponseAnswer
|
|
}
|
|
|
|
hasNS := hasNSRecords(msg.Ns)
|
|
if hasNS && !msg.Authoritative {
|
|
return ResponseReferral
|
|
}
|
|
|
|
if hasNS {
|
|
return ResponseNODATA
|
|
}
|
|
|
|
return ResponseNODATA
|
|
}
|
|
|
|
func hasNSRecords(rrs []dns.RR) bool {
|
|
for _, rr := range rrs {
|
|
if _, ok := rr.(*dns.NS); ok {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func extractCNAMEChain(msg *dns.Msg) []string {
|
|
var chain []string
|
|
seen := make(map[string]bool)
|
|
for _, rr := range msg.Answer {
|
|
if cname, ok := rr.(*dns.CNAME); ok {
|
|
target := cname.Target
|
|
if !seen[target] {
|
|
seen[target] = true
|
|
chain = append(chain, target)
|
|
}
|
|
}
|
|
}
|
|
return chain
|
|
}
|
|
|
|
func extractDNAMEMappings(msg *dns.Msg) []DNAMEMapping {
|
|
var mappings []DNAMEMapping
|
|
for _, rr := range msg.Answer {
|
|
if dname, ok := rr.(*dns.DNAME); ok {
|
|
mappings = append(mappings, DNAMEMapping{
|
|
Owner: dns.Fqdn(dname.Hdr.Name),
|
|
Target: dns.Fqdn(dname.Target),
|
|
})
|
|
}
|
|
}
|
|
return mappings
|
|
}
|
|
|
|
// SynthesizeCNAMEFromDNAME computes the CNAME target for queryName given a DNAME mapping.
|
|
// Returns empty string if queryName is not a strict subdomain of dnameOwner.
|
|
func SynthesizeCNAMEFromDNAME(queryName, dnameOwner, dnameTarget string) string {
|
|
q := strings.ToLower(dns.Fqdn(queryName))
|
|
owner := strings.ToLower(dns.Fqdn(dnameOwner))
|
|
target := strings.ToLower(dns.Fqdn(dnameTarget))
|
|
|
|
if !dns.IsSubDomain(owner, q) || q == owner {
|
|
return ""
|
|
}
|
|
prefix := strings.TrimSuffix(q, owner)
|
|
return prefix + target
|
|
}
|
|
|
|
func IsTruncated(msg *dns.Msg) bool {
|
|
return msg != nil && msg.Truncated
|
|
}
|
|
|
|
func RcodeName(msg *dns.Msg) string {
|
|
if msg == nil {
|
|
return "UNKNOWN"
|
|
}
|
|
return dns.RcodeToString[msg.Rcode]
|
|
}
|
|
|
|
func ExtractAnswers(msg *dns.Msg) []dns.RR {
|
|
if msg == nil {
|
|
return nil
|
|
}
|
|
return msg.Answer
|
|
}
|
|
|
|
func ExtractAuthority(msg *dns.Msg) []dns.RR {
|
|
if msg == nil {
|
|
return nil
|
|
}
|
|
return msg.Ns
|
|
}
|
|
|
|
func ExtractCNAMEChain(msg *dns.Msg) []string {
|
|
if msg == nil {
|
|
return nil
|
|
}
|
|
return extractCNAMEChain(msg)
|
|
}
|
|
|
|
func IsReferral(msg *dns.Msg) bool {
|
|
if msg == nil || msg.Rcode != dns.RcodeSuccess || len(msg.Answer) > 0 {
|
|
return false
|
|
}
|
|
return hasNSRecords(msg.Ns) && !msg.Authoritative
|
|
}
|
|
|
|
func IsNODATA(msg *dns.Msg) bool {
|
|
if msg == nil || msg.Rcode != dns.RcodeSuccess {
|
|
return false
|
|
}
|
|
if len(msg.Answer) > 0 {
|
|
return false
|
|
}
|
|
if IsReferral(msg) {
|
|
return false
|
|
}
|
|
return true
|
|
}
|
|
|
|
func HasCNAMEChain(msg *dns.Msg) bool {
|
|
if msg == nil {
|
|
return false
|
|
}
|
|
return len(extractCNAMEChain(msg)) > 0
|
|
}
|
|
|
|
func FormatRecord(rr dns.RR) string {
|
|
if rr == nil {
|
|
return ""
|
|
}
|
|
return rr.String()
|
|
}
|