Repository navigation
fix: update Hickory DNS for macOS network resolution - #349
Conversation
✅ Deploy Preview for yarn-v6 ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
⏱️ Benchmark Resultsgatsby install-full-cold
📊 Raw benchmark data (gatsby install-full-cold)Base times: 4.352s, 4.263s, 4.402s, 4.346s, 4.360s, 4.453s, 4.340s, 4.400s, 4.411s, 4.389s, 4.373s, 4.313s, 4.231s, 4.247s, 4.231s, 4.340s, 4.284s, 4.376s, 4.308s, 4.266s, 4.286s, 4.331s, 4.329s, 4.254s, 4.326s, 4.317s, 4.417s, 4.326s, 4.366s, 4.282s Head times: 4.274s, 4.280s, 4.311s, 4.239s, 4.302s, 4.382s, 4.345s, 4.317s, 4.283s, 4.306s, 4.374s, 4.314s, 4.311s, 4.359s, 4.348s, 4.380s, 4.358s, 4.376s, 4.297s, 4.351s, 4.280s, 4.369s, 4.373s, 4.372s, 4.333s, 4.300s, 4.314s, 4.321s, 4.316s, 4.333s gatsby install-cache-only
📊 Raw benchmark data (gatsby install-cache-only)Base times: 1.299s, 1.322s, 1.311s, 1.312s, 1.305s, 1.311s, 1.322s, 1.315s, 1.300s, 1.313s, 1.310s, 1.290s, 1.307s, 1.316s, 1.318s, 1.325s, 1.319s, 1.323s, 1.336s, 1.315s, 1.317s, 1.308s, 1.318s, 1.308s, 1.313s, 1.327s, 1.332s, 1.322s, 1.309s, 1.329s Head times: 1.320s, 1.323s, 1.332s, 1.324s, 1.315s, 1.318s, 1.268s, 1.310s, 1.306s, 1.322s, 1.330s, 1.321s, 1.295s, 1.314s, 1.406s, 1.302s, 1.315s, 1.306s, 1.963s, 1.307s, 1.307s, 1.309s, 1.341s, 1.349s, 1.371s, 1.361s, 1.354s, 1.369s, 1.346s, 1.342s gatsby install-cache-and-lock (warm, with lockfile)
📊 Raw benchmark data (gatsby install-cache-and-lock (warm, with lockfile))Base times: 0.362s, 0.365s, 0.366s, 0.373s, 0.364s, 0.361s, 0.366s, 0.368s, 0.361s, 0.366s, 0.366s, 0.370s, 0.363s, 0.366s, 0.370s, 0.366s, 0.370s, 0.372s, 0.365s, 0.364s, 0.367s, 0.355s, 0.361s, 0.360s, 0.364s, 0.374s, 0.365s, 0.360s, 0.368s, 0.369s Head times: 0.365s, 0.365s, 0.368s, 0.370s, 0.376s, 0.371s, 0.380s, 0.375s, 0.374s, 0.381s, 0.366s, 0.367s, 0.375s, 0.369s, 0.369s, 0.367s, 0.371s, 0.365s, 0.368s, 0.368s, 0.366s, 0.368s, 0.364s, 0.366s, 0.374s, 0.373s, 0.370s, 0.368s, 0.367s, 0.371s |
|
|
||
| builder.options_mut().ip_strategy = LookupIpStrategy::Ipv4AndIpv6; | ||
| builder.build() | ||
| .expect("Failed to build a DNS resolver") |
There was a problem hiding this comment.
Hickory 0.26 changed ResolverBuilder::build() from returning a TokioResolver directly to returning Result<TokioResolver, NetError>. new_resolver() still returns TokioResolver, so this handles the new result type. It keeps the existing fail-fast initialization behavior (builder_tokio() is already handled with expect above); this line is an API adaptation, with no intended change to DNS lookup behavior.
Motivation
Some macOS users on tunnel-backed networks see cold installs stall until Yarn reports
Task timeout. An initial test with this build on an affected setup appears to resolve the issue.The most relevant upstream change is Hickory DNS's macOS system configuration update: v0.25 read DNS settings from
/etc/resolv.conf, while v0.26 reads the macOS System Configuration API. That could explain why resolution behaves differently across machines and network setups. The new code reads the global DNS entry; this is a plausible explanation, not a confirmed diagnosis of the tunnel's DNS behavior.Reqwest also changes here because v0.13.4 is its first release using Hickory 0.26. The test build changed both libraries, so it does not isolate which change fixed the timeout.
Changes
Compatibility and review notes
build()result. On macOS, Hickory now reads the global DNS configuration through the System Configuration API instead of/etc/resolv.conf. It does not read supplemental per-domain resolvers there. Hickory also enables EDNS by default and trusts negative responses from system resolvers by default, so DNS behavior on unusual VPN or resolver setups deserves review. Release notesrustls-tlsfeature becamerustls. Native Yarn clients already select Rustls explicitly, but reqwest now uses aws-lc by default and the platform certificate verifier for roots;default-tlsalso selects Rustls on the Browserpod target. Please review private CA, client certificate, and proxy paths. The newly optionalqueryandformAPIs are not used here. Breaking changesQA Instructions
Note
Medium Risk
Touches all HTTPS/DNS resolution paths via reqwest and Hickory upgrades; TLS stack shifts toward rustls/aws-lc with platform verification instead of native-tls/openssl.
Overview
Upgrades Hickory DNS (
hickory-resolver0.25.2 → 0.26.3) and reqwest (0.12 → 0.13.5) so installs use Hickory’s macOS system DNS configuration instead of/etc/resolv.conf, addressing reported cold-install stalls on some tunnel-backed networks.packages/zpmandpackages/zpm-switchswitch the non-browserpod reqwest feature fromrustls-tlstorustls(reqwest 0.13 rename).new_resolverinhttp.rsnow calls.expect(...)on Hickory’s falliblebuild()afterbuilder_tokio().The lockfile consolidates on a single reqwest 0.13.5 stack (rustls + platform verifier, Hickory 0.26 /
hickory-net), dropping the previous OpenSSL/native-tls/hyper-tlspath for HTTP clients.Reviewed by Cursor Bugbot for commit 900b895. Bugbot is set up for automated code reviews on this repo. Configure here.