Awesome Reviewers expert instructions

domains / orchestration / apple/container

DNS and Timeout Rules

When implementing networking features (DNS, proxies, RPC/XPC), make behavior consistent with the correct layer and avoid imposing policy that breaks end-to-end semantics.

raw .md Networking Swift updated

When implementing networking features (DNS, proxies, RPC/XPC), make behavior consistent with the correct layer and avoid imposing policy that breaks end-to-end semantics.

Guidelines: 1) Separate DNS defaults by layer

  • Keep host/apiserver DNS defaults distinct from in-container resolv.conf defaults.

2) Normalize DNS names end-to-end

  • Ensure parse/store/lookup all normalize the same way (e.g., treat foo and foo. consistently).
  • Add focused unit tests for normalization.

3) Make forwarding timeouts cascade

  • If one service forwards an XPC call to another, don’t add an arbitrary timeout in the outer layer when the inner layer is responsible for timing out. Otherwise, pick a timeout based on the specific operation.

4) Decode DNS safely

  • Validate compression pointers and guard against malformed packets that could cause loops.

Example (timeout cascading):

// In the forwarding client: remove arbitrary timeout when the downstream call cascades timeouts.
let _ = try await xpcSend(message: request)

Example (DNS normalization idea):

func normalize(_ hostname: String) -> String {
    let s = hostname.hasSuffix(".") ? String(hostname.dropLast()) : hostname
    return s.lowercased()
}
Source discussions