watcher: notify NS query failure and recovery (closes #104)
check / check (push) Successful in 1m31s

LookupAllRecords now returns each nameserver's response, so the
watcher saves its status: ok when it answered, NXDOMAIN and no records
included, and error with the reason when it timed out, answered
SERVFAIL or REFUSED, or could not be reached. A nameserver that starts
failing sends NS Failure and one that answers again sends NS Recovery.
A failing nameserver is left out of the record change and
inconsistency comparisons. The resolver used to report REFUSED and
network errors as an answer with no records; they are now errors. A
lookup cut short by its context now returns an error instead of a
failure of the nameserver it was querying.

Model: opus-5-5
This commit was merged in pull request #175.
This commit is contained in:
2026-10-01 22:23:33 +02:00
parent fcd4f7e2c2
commit 8f11ef0038
11 changed files with 583 additions and 91 deletions
+3 -2
View File
@@ -5,6 +5,7 @@ import (
"context"
"sneak.berlin/go/dnswatcher/internal/portcheck"
"sneak.berlin/go/dnswatcher/internal/resolver"
"sneak.berlin/go/dnswatcher/internal/tlscheck"
)
@@ -17,11 +18,11 @@ type DNSResolver interface {
) ([]string, error)
// LookupAllRecords queries all record types for a hostname,
// returning results keyed by nameserver then record type.
// returning each nameserver's response keyed by nameserver.
LookupAllRecords(
ctx context.Context,
hostname string,
) (map[string]map[string][]string, error)
) (map[string]*resolver.NameserverResponse, error)
// ResolveIPAddresses resolves a hostname to all IP addresses.
ResolveIPAddresses(