Repository navigation
Remove the public DNS fallback, and correct the privacy page - #551
Merged
Merged
Conversation
… page When the system resolver returned any error, including a plain "no records" answer, netscli-core asked Cloudflare's public resolver the same question. That sent names users looked up to a third party, unencrypted and undisclosed, from the CLI, TUI, desktop app and MCP server, while the privacy page said lookups only reach the DNS servers you ask. The fallback is gone: lookups use the system resolver only, and a refusal from it is reported as is. NETSCLI_DNS_FALLBACK no longer does anything. A test fails if any resolver other than the system one is built again, because nothing else would notice: a fallback changes no result, only where the question goes. The privacy page now discloses the fallback in 0.3.4 and earlier and how to turn it off there, the CLI history database, and that Cloudflare proxies every page of the site. The cli.md example that showed a public_fallback answer is regenerated from a real run.
Contributor
|
Site preview: https://pr-551.netscli-site-preview.pages.dev Built from de00783 with Production is unaffected: netscli.com is served from GitHub Pages via |
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Audit finding C1 and H2 (
.agent-evidence/audit-2026-10-07/AUDIT.md, local only).What was wrong
netscli-coreasked Cloudflare's public resolver (1.1.1.1) the same question.dns, and every command given a host name, in the CLI, TUI, desktop app and MCP server.NETSCLI_DNS_FALLBACK=0, was documented nowhere.What changes
dns/resolver.rskeeps only the system resolver.lookup.rsreports the system resolver's own error, so a refusal reads as a refusal.resolver_sourcestays in the output, alwayssystem, so saved results and scripts keep working.ResolverConfig,builder_with_configor a public preset. I checked it by putting aCLOUDFLAREmention back, and the test failed.privacy.tsnow covers:cli.mdexample that showed apublic_fallbackanswer is regenerated from a real runresult-model.mdandoperations.mdsay where lookups goWorth knowing
On this machine the router's DNS server refuses MX queries.
nslookup -type=MX netscli.comgets "Query refused" too. That is why the fallback existed. Without it,netscli dns netscli.com --record MXnow fails here with "MX lookup failed: DNS error: error response: Query Refused", the same as the system's own tools. If you want lookups against a server you choose, a--serveroption would be the honest replacement. It is not in this PR.Checked
cargo fmt --all --checkcargo clippy -p netscli-core -p netscli --all-targets -- -D warningscargo test -p netscli-core: 125 tests plus the integration tests passnetscli dns netscli.com --record A --csvand--mdanswer fromsystemDnsRecord.ts's comment changed.npm run check: 0 errorsMerging this deploys the corrected privacy page.