pdns-recursor-rd0-refused
Purpose
When Conduit forwards to PowerDNS Recursor, a client query with the recursion-desired bit cleared (RD=0) can receive REFUSED for a name the Recursor would answer successfully if RD were set — that is Recursor’s default policy for non-recursive queries, not a Conduit refusal. Operators should see that same REFUSED through Conduit (Conduit does not invent an answer or rewrite the rcode).
How it works
- The Recursor under test is given a local auth-zone name that answers A successfully when RD=1.
- The client queries that name via Conduit with RD cleared (for example
dig +nord). - The response must be REFUSED and must match a direct query to the Recursor with the same flags.
Outcomes
| Outcome | Meaning for operators |
|---|---|
| pass | Not expected for this case; a matching result is reported as characterized. |
| fail | Through Conduit the client did not get REFUSED, or Conduit’s answer disagreed with querying the Recursor directly. |
| skip | Peer is not PowerDNS Recursor for this matrix (or profile out of scope). |
| characterized | Expected: RD=0 yields REFUSED through Conduit, matching the Recursor’s own reply. |
Matrix: peer (by publisher)
Suites: full
Oracles: property, parity, differential