watcher: notify nameserver address changes (closes #105)
check / check (push) Failing after 2m14s
check / check (push) Failing after 2m14s
Each domain check now looks up the addresses every nameserver's name resolves to, with the resolver's ResolveIPAddresses, and saves them sorted in the domain's state. A nameserver that stays in the delegation and resolves to different addresses sends one NS Address Change notification naming the domain, the nameserver and the old and new addresses. Added or removed nameservers get only the NS change notification. A failed or empty lookup keeps the previous addresses, because the resolver returns no address without an error when every server it asks times out. State files without the field load, and the next check fills it in silently. Watcher tests that run domain checks use example.com, which has two nameservers, to stay within the per-attempt limit. Model: opus-5-5
This commit is contained in:
@@ -0,0 +1,147 @@
|
||||
package watcher_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"log/slog"
|
||||
"reflect"
|
||||
"testing"
|
||||
|
||||
"sneak.berlin/go/dnswatcher/internal/livednstest"
|
||||
"sneak.berlin/go/dnswatcher/internal/resolver"
|
||||
"sneak.berlin/go/dnswatcher/internal/watcher"
|
||||
)
|
||||
|
||||
const domain = "example.net"
|
||||
|
||||
func TestNSAddressChangeAlerts(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
// Each case is the nameserver addresses saved by the previous check
|
||||
// and by the current one.
|
||||
tests := []struct {
|
||||
name string
|
||||
prev, current map[string][]string
|
||||
want int
|
||||
}{
|
||||
{
|
||||
"same addresses",
|
||||
map[string][]string{nsA: {ip1, ip2}},
|
||||
map[string][]string{nsA: {ip1, ip2}},
|
||||
0,
|
||||
},
|
||||
{
|
||||
"same addresses in another order",
|
||||
map[string][]string{nsA: {ip2, ip1}},
|
||||
map[string][]string{nsA: {ip1, ip2}},
|
||||
0,
|
||||
},
|
||||
{
|
||||
"address replaced",
|
||||
map[string][]string{nsA: {ip1}},
|
||||
map[string][]string{nsA: {ip2}},
|
||||
1,
|
||||
},
|
||||
{
|
||||
"address added",
|
||||
map[string][]string{nsA: {ip1}},
|
||||
map[string][]string{nsA: {ip1, ip2}},
|
||||
1,
|
||||
},
|
||||
{
|
||||
"two nameservers changed",
|
||||
map[string][]string{nsA: {ip1}, nsB: {ip2}},
|
||||
map[string][]string{nsA: {ip3}, nsB: {ip3}},
|
||||
2,
|
||||
},
|
||||
{
|
||||
"nameserver added",
|
||||
map[string][]string{nsA: {ip1}},
|
||||
map[string][]string{nsA: {ip1}, nsB: {ip2}},
|
||||
0,
|
||||
},
|
||||
{
|
||||
"nameserver removed",
|
||||
map[string][]string{nsA: {ip1}, nsB: {ip2}},
|
||||
map[string][]string{nsA: {ip1}},
|
||||
0,
|
||||
},
|
||||
{
|
||||
"state file from before addresses were saved",
|
||||
nil,
|
||||
map[string][]string{nsA: {ip1}, nsB: {ip2}},
|
||||
0,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
notifier := &mockNotifier{}
|
||||
w := watcher.NewForTest(nil, nil, nil, nil, nil, notifier)
|
||||
|
||||
w.DetectNSAddressChanges(t.Context(), domain, tt.prev, tt.current)
|
||||
|
||||
got := len(notifier.getNotifications())
|
||||
if got != tt.want {
|
||||
t.Errorf("sent %d address changes, want %d", got, tt.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestNSAddressChangeAlertNamesDomainNameserverAndAddresses(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
notifier := &mockNotifier{}
|
||||
w := watcher.NewForTest(nil, nil, nil, nil, nil, notifier)
|
||||
|
||||
w.DetectNSAddressChanges(
|
||||
t.Context(), domain,
|
||||
map[string][]string{nsA: {ip1}},
|
||||
map[string][]string{nsA: {ip2, ip3}},
|
||||
)
|
||||
|
||||
want := notification{
|
||||
Title: "NS Address Change: " + domain,
|
||||
Message: "Domain: " + domain + "\nNameserver: " + nsA +
|
||||
"\nOld: " + ip1 + "\nNew: " + ip2 + ", " + ip3,
|
||||
Priority: "warning",
|
||||
}
|
||||
|
||||
got := notifier.getNotifications()
|
||||
if len(got) != 1 || got[0] != want {
|
||||
t.Errorf("sent %v, want %v", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
// TestNameserverWithNoAddressKeepsPrevious looks up nameserver names
|
||||
// under .invalid, which live DNS never resolves. The one with addresses
|
||||
// saved by the previous check keeps them; the one without gets none.
|
||||
func TestNameserverWithNoAddressKeepsPrevious(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
w := watcher.NewForTest(
|
||||
nil, nil, resolver.NewFromLogger(slog.Default()), nil, nil, nil,
|
||||
)
|
||||
|
||||
prev := map[string][]string{oldNS1: {oldIP}}
|
||||
|
||||
var got map[string][]string
|
||||
|
||||
// The result is the same whether or not live DNS answers, so the
|
||||
// lookup is not retried.
|
||||
_ = livednstest.Run(func(ctx context.Context) error {
|
||||
got = w.ResolveNameserverAddresses(
|
||||
ctx, []string{oldNS1, oldNS2}, prev,
|
||||
)
|
||||
|
||||
return nil
|
||||
})
|
||||
|
||||
if !reflect.DeepEqual(got, prev) {
|
||||
t.Errorf("saved %v, want %v", got, prev)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user