resolver, watcher: a record type whose query fails keeps its previous records (closes #231)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
The resolver lists in FailedTypes each record type whose query to a nameserver got no usable reply: none after two tries, an error reply, a referral, or a truncated reply whose TCP retry failed. Records holds nothing for such a type, never none or the part that fit. A nameserver that answered no type has failed, as before. The watcher keeps the previous check's records for a failed type; when that check did not know them either (first check, new or failing nameserver), the type is saved in failedTypes and left out of record and inconsistency comparisons. ResolveIPAddresses no longer counts a nameserver whose A, AAAA or CNAME query failed as an answer. Model: opus-5-5
This commit is contained in:
@@ -80,7 +80,8 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
different addresses than on the previous check. A nameserver added or
|
||||
removed gets only the NS change notification. When the lookup of a
|
||||
nameserver's addresses fails or finds none, its previous addresses are
|
||||
kept and nothing is sent.
|
||||
kept and nothing is sent. The lookup fails when no nameserver it asks
|
||||
answers every one of its queries, for A, AAAA and CNAME.
|
||||
|
||||
### DNS Hostname Monitoring (Subdomains)
|
||||
|
||||
@@ -91,6 +92,15 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
its last two labels (a name under `co.uk`, or in a delegated subdomain).
|
||||
- Queries **each** authoritative nameserver independently for **all** record
|
||||
types: A, AAAA, CNAME, MX, TXT, SRV, CAA, NS.
|
||||
- Each record type is a query of its own. When a nameserver answers some types
|
||||
but the query for another gets no usable reply (no reply after two tries, an
|
||||
error reply such as SERVFAIL, or a reply too large for UDP whose retry over
|
||||
TCP fails), that type keeps the records saved for the nameserver by the
|
||||
previous check, and no record change or inconsistency is reported for it. When
|
||||
there are none to keep, because the nameserver was new or failing on the
|
||||
previous check, the type is listed in the nameserver's `failedTypes` and left
|
||||
out of comparisons until it answers. A nameserver none of whose queries got a
|
||||
usable reply has failed (see NS query failure below).
|
||||
- Stores results **per nameserver**. The state for a hostname is not a merged
|
||||
view — it is a map from nameserver to record set.
|
||||
- DNS names inside record values (CNAME, MX, SRV and NS targets) are stored in
|
||||
@@ -502,7 +512,7 @@ reachability:
|
||||
|
||||
| Status | Meaning |
|
||||
| ------- | -------------------------------------------------------- |
|
||||
| `ok` | Query succeeded, records are current |
|
||||
| `ok` | Query succeeded, records are current except as below |
|
||||
| `error` | Query failed (timeout, SERVFAIL, REFUSED, network error) |
|
||||
|
||||
A nameserver that answers NXDOMAIN or with no records has status `ok` and empty
|
||||
@@ -511,6 +521,11 @@ nameservers, has status `error`, empty `records`, and the reason in `error`. A
|
||||
certificate entry whose TLS connection or handshake failed likewise has status
|
||||
`error`, the reason in `error`, and the certificate fields left empty or zero.
|
||||
|
||||
A nameserver with status `ok` whose query for one record type failed holds that
|
||||
type's records from the previous check, which may not be current. When there
|
||||
were none to keep, the type is listed in `failedTypes`, which is left out when
|
||||
empty, and `records` holds nothing for it.
|
||||
|
||||
`nameserverAddresses` lists, by nameserver, the sorted addresses its name
|
||||
resolves to. A state file without it loads, and the next check fills it in
|
||||
without a notification.
|
||||
|
||||
Reference in New Issue
Block a user