Skip to content

fix: update Hickory DNS for macOS network resolution - #349

Merged
arcanis merged 1 commit into
mainfrom
rui.martins/hickory-dns-0263-test
Oct 6, 2026
Merged

arcanis merged 1 commit into
mainfrom
rui.martins/hickory-dns-0263-test

Conversation

@ruimartin

@ruimartin ruimartin commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Motivation

Some macOS users on tunnel-backed networks see cold installs stall until Yarn reports Task timeout. An initial test with this build on an affected setup appears to resolve the issue.

The most relevant upstream change is Hickory DNS's macOS system configuration update: v0.25 read DNS settings from /etc/resolv.conf, while v0.26 reads the macOS System Configuration API. That could explain why resolution behaves differently across machines and network setups. The new code reads the global DNS entry; this is a plausible explanation, not a confirmed diagnosis of the tunnel's DNS behavior.

Reqwest also changes here because v0.13.4 is its first release using Hickory 0.26. The test build changed both libraries, so it does not isolate which change fixed the timeout.

Changes

  • Upgrade Hickory DNS to 0.26.3 and reqwest to 0.13.5, keeping one Hickory version in the dependency tree.
  • Adapt Yarn's custom resolver to Hickory's fallible builder API and update reqwest's renamed Rustls feature.

Compatibility and review notes

  • Hickory 0.26: The resolver and configuration APIs changed; this PR handles the new fallible build() result. On macOS, Hickory now reads the global DNS configuration through the System Configuration API instead of /etc/resolv.conf. It does not read supplemental per-domain resolvers there. Hickory also enables EDNS by default and trusts negative responses from system resolvers by default, so DNS behavior on unusual VPN or resolver setups deserves review. Release notes
  • reqwest 0.13: The rustls-tls feature became rustls. Native Yarn clients already select Rustls explicitly, but reqwest now uses aws-lc by default and the platform certificate verifier for roots; default-tls also selects Rustls on the Browserpod target. Please review private CA, client certificate, and proxy paths. The newly optional query and form APIs are not used here. Breaking changes

QA Instructions

  • Initial field testing suggests the timeout is resolved, but the cause has not been isolated between Hickory and reqwest.
  • CI tests should all pass

Note

Medium Risk
Touches all HTTPS/DNS resolution paths via reqwest and Hickory upgrades; TLS stack shifts toward rustls/aws-lc with platform verification instead of native-tls/openssl.

Overview
Upgrades Hickory DNS (hickory-resolver 0.25.2 → 0.26.3) and reqwest (0.12 → 0.13.5) so installs use Hickory’s macOS system DNS configuration instead of /etc/resolv.conf, addressing reported cold-install stalls on some tunnel-backed networks.

packages/zpm and packages/zpm-switch switch the non-browserpod reqwest feature from rustls-tls to rustls (reqwest 0.13 rename). new_resolver in http.rs now calls .expect(...) on Hickory’s fallible build() after builder_tokio().

The lockfile consolidates on a single reqwest 0.13.5 stack (rustls + platform verifier, Hickory 0.26 / hickory-net), dropping the previous OpenSSL/native-tls/hyper-tls path for HTTP clients.

Reviewed by Cursor Bugbot for commit 900b895. Bugbot is set up for automated code reviews on this repo. Configure here.

@netlify

netlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for yarn-v6 ready!

Name Link
🔨 Latest commit 900b895
🔍 Latest deploy log https://app.netlify.com/projects/yarn-v6/deploys/6abe27ed33ddf20008ee276f
😎 Deploy Preview https://deploy-preview-349--yarn-v6.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

⏱️ Benchmark Results

gatsby install-full-cold

Metric Base Head Difference
Mean 4.331s 4.327s -0.08% ✅
Median 4.330s 4.319s -0.26% ✅
Min 4.231s 4.239s
Max 4.453s 4.382s
Std Dev 0.058s 0.037s
📊 Raw benchmark data (gatsby install-full-cold)

Base times: 4.352s, 4.263s, 4.402s, 4.346s, 4.360s, 4.453s, 4.340s, 4.400s, 4.411s, 4.389s, 4.373s, 4.313s, 4.231s, 4.247s, 4.231s, 4.340s, 4.284s, 4.376s, 4.308s, 4.266s, 4.286s, 4.331s, 4.329s, 4.254s, 4.326s, 4.317s, 4.417s, 4.326s, 4.366s, 4.282s

Head times: 4.274s, 4.280s, 4.311s, 4.239s, 4.302s, 4.382s, 4.345s, 4.317s, 4.283s, 4.306s, 4.374s, 4.314s, 4.311s, 4.359s, 4.348s, 4.380s, 4.358s, 4.376s, 4.297s, 4.351s, 4.280s, 4.369s, 4.373s, 4.372s, 4.333s, 4.300s, 4.314s, 4.321s, 4.316s, 4.333s


gatsby install-cache-only

Metric Base Head Difference
Mean 1.315s 1.348s +2.52% ⚠️
Median 1.315s 1.322s +0.53% ⚠️
Min 1.290s 1.268s
Max 1.336s 1.963s
Std Dev 0.010s 0.119s
📊 Raw benchmark data (gatsby install-cache-only)

Base times: 1.299s, 1.322s, 1.311s, 1.312s, 1.305s, 1.311s, 1.322s, 1.315s, 1.300s, 1.313s, 1.310s, 1.290s, 1.307s, 1.316s, 1.318s, 1.325s, 1.319s, 1.323s, 1.336s, 1.315s, 1.317s, 1.308s, 1.318s, 1.308s, 1.313s, 1.327s, 1.332s, 1.322s, 1.309s, 1.329s

Head times: 1.320s, 1.323s, 1.332s, 1.324s, 1.315s, 1.318s, 1.268s, 1.310s, 1.306s, 1.322s, 1.330s, 1.321s, 1.295s, 1.314s, 1.406s, 1.302s, 1.315s, 1.306s, 1.963s, 1.307s, 1.307s, 1.309s, 1.341s, 1.349s, 1.371s, 1.361s, 1.354s, 1.369s, 1.346s, 1.342s


gatsby install-cache-and-lock (warm, with lockfile)

Metric Base Head Difference
Mean 0.366s 0.370s +1.22% ⚠️
Median 0.366s 0.369s +0.82% ⚠️
Min 0.355s 0.364s
Max 0.374s 0.381s
Std Dev 0.004s 0.004s
📊 Raw benchmark data (gatsby install-cache-and-lock (warm, with lockfile))

Base times: 0.362s, 0.365s, 0.366s, 0.373s, 0.364s, 0.361s, 0.366s, 0.368s, 0.361s, 0.366s, 0.366s, 0.370s, 0.363s, 0.366s, 0.370s, 0.366s, 0.370s, 0.372s, 0.365s, 0.364s, 0.367s, 0.355s, 0.361s, 0.360s, 0.364s, 0.374s, 0.365s, 0.360s, 0.368s, 0.369s

Head times: 0.365s, 0.365s, 0.368s, 0.370s, 0.376s, 0.371s, 0.380s, 0.375s, 0.374s, 0.381s, 0.366s, 0.367s, 0.375s, 0.369s, 0.369s, 0.367s, 0.371s, 0.365s, 0.368s, 0.368s, 0.366s, 0.368s, 0.364s, 0.366s, 0.374s, 0.373s, 0.370s, 0.368s, 0.367s, 0.371s

Comment thread packages/zpm/src/http.rs

builder.options_mut().ip_strategy = LookupIpStrategy::Ipv4AndIpv6;
builder.build()
.expect("Failed to build a DNS resolver")

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hickory 0.26 changed ResolverBuilder::build() from returning a TokioResolver directly to returning Result<TokioResolver, NetError>. new_resolver() still returns TokioResolver, so this handles the new result type. It keeps the existing fail-fast initialization behavior (builder_tokio() is already handled with expect above); this line is an API adaptation, with no intended change to DNS lookup behavior.

@ruimartin
ruimartin marked this pull request as ready for review October 1, 2026 10:36
@ruimartin
ruimartin requested a review from arcanis October 1, 2026 10:36
@arcanis
arcanis merged commit 1db9c42 into main Oct 6, 2026
25 checks passed
@arcanis
arcanis deleted the rui.martins/hickory-dns-0263-test branch October 6, 2026 21:57

This branch was successfully deployed

1 active deployment
test-reports — 900b895a Deployed Oct 1, 2026 by ruimartin via Reporting test results #1361
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants