Defer fallback DNS initialization for literal targets - #949
Merged
Merged
Conversation
bee-san
force-pushed
the
perf/lazy-dns-resolver
branch
from
October 2, 2026 09:36
5c88b77 to
b0dedb6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Literal IP and CIDR targets currently construct Hickory's fallback resolver, including its runtime and hosts-file load, even when no DNS is needed. Initialize it only when a fallback lookup needs it, then reuse it for the remaining targets and exclusions. Public parsing signatures, system-DNS-before-fallback order, file handling, deduplication and exclusions are preserved.
This branch includes current master
67c08a33100362c54b56fde784b0fd234f70fa11(#951 and #954). Its diff against master contains only the DNS implementation, focused tests and benchmark report.Matched startup benchmark
Compared master
67c08a3with implementationa05592a8a88b77ad85d961137943dfadfe98b612(the final head adds only this report). Release/LTO, Rust 1.98.1, Intel Core Ultra 7 165U, Linux 7.2.6-1-cachyos; binaries pinned to CPUs 0–3 and the harness to CPUs 8–9. Each workload has twenty measured samples and two warmups per build, alternating A/B and B/A. No concurrent builds.All 88 invocations ran in a private network namespace, excluded their only requested port, disabled scripts/configuration and returned the expected empty result. No scan traffic was sent. The candidate's literal-IP syscall trace records no hosts/resolver-file reads, sockets, connects or sends.
This host has a 2,760,051-byte hosts file. Systems with smaller hosts files save less; these are whole-process startup timings, not socket-throughput claims. Reproduction, setup, hashes and raw samples.
Validation
CARGO_TARGET_DIR=/tmp/rustscan-951-validation-6kq_af7m/target-head just test: passed on the combined master/DNS implementation; 76 tests passed, zero failures, one pre-existing ignored doctest. Both Clippy checks, formatting and documentation build passed.CARGO_TARGET_DIR=/tmp/rustscan-speed-20261002-9to0ine_/target cargo build --release --locked: passed for both builds before measurement.unshare --user --map-root-user --net python /tmp/rustscan-speed-20261002-9to0ine_/measure-dns-current.py: all 88 invocations passed; all raw samples included in the report.e3abce7ce984d70045c93f62106d013491b80ed9against master67c08a3: four test jobs and four benchmark jobs passed. The release comparisons ran 792 measured invocations, with nine interleaved samples per build/scenario and 27 for the one-port case. Every expected TCP/UDP listener was found; zero subprocess failures, result mismatches or diagnostic scans. The existing wall-time/throughput/RSS gates passed on every platform. Raw measurements are in the workflow artifacts. The runner hosts files are small, so these results validate scan behavior and comparable throughput rather than reproducing the large-hosts-file startup saving.git diff --check, complete branch self-review and report/link inspection passed. The worktree is clean.Simplification review retained the existing parsing paths and public wrappers; standard-library
LazyCellowns resolver initialization. No new dependencies, alternate resolver, retry policy or resource limit was added. The scan comparisons use the existing CI harness and its unchanged listener and performance gates.Merged-revision verification
Merged as
32d7d2cb176ee3aabdec54886c22ff631e8eb18a. Its tree exactly matches the tested head (7a3d448fe48a72ab3e2bebd335fb158622e2bdfa). Localmasterwas fast-forwarded, preserving the original working branch and checkout.x86_64-linux-rustscan.tar.gzartifact and verified its SHA-256 against the packaged checksum:1c34d28e27afbc79edcd10cc99dcf814cc8c1533c77a3026f3300762c015d069. The extracted binary's--versionand--helpcommands both exited 0 (rustscan 2.4.1), without performing scans.