resolver, watcher: a record type whose query fails keeps its previous records (closes #231)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
The resolver lists in FailedTypes each record type whose query to a nameserver got no usable reply (no reply, a code other than NOERROR or NXDOMAIN, a referral, or a truncated reply whose TCP retry failed) and logs it unless shutdown cut it short. A nameserver that answered no type has failed. The watcher saves such a type in failedTypes with the previous check's records, leaves it out of the comparison with other nameservers on that check, and compares it with the next answer. When the previous check did not know its records either, it is also in unknownTypes and not compared until it answers. A nameserver whose A, AAAA or CNAME query failed is no answer when following a CNAME or resolving addresses. Model: opus-5-5
This commit was merged in pull request #234.
This commit is contained in:
@@ -80,7 +80,8 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
different addresses than on the previous check. A nameserver added or
|
||||
removed gets only the NS change notification. When the lookup of a
|
||||
nameserver's addresses fails or finds none, its previous addresses are
|
||||
kept and nothing is sent.
|
||||
kept and nothing is sent. The lookup fails when no nameserver it asks
|
||||
answers every one of its queries, for A, AAAA and CNAME.
|
||||
- Also watches the domain's own records as a hostname's are watched (see DNS
|
||||
Hostname Monitoring below): its A, AAAA, CNAME, MX, TXT, SRV, CAA and NS
|
||||
records, stored per nameserver. Their changes are notified as a hostname's
|
||||
@@ -97,6 +98,19 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
its last two labels (a name under `co.uk`, or in a delegated subdomain).
|
||||
- Queries **each** authoritative nameserver independently for **all** record
|
||||
types: A, AAAA, CNAME, MX, TXT, SRV, CAA, NS.
|
||||
- Each record type is a query of its own. When a nameserver answers some types
|
||||
but the query for another gets no usable reply (no reply after two tries, an
|
||||
error reply such as SERVFAIL, a referral, or a reply too large for UDP whose
|
||||
retry over TCP fails), the failure is logged with the reason, and the type is
|
||||
listed in the nameserver's `failedTypes` and keeps the records saved for the
|
||||
nameserver by the previous check. On that check those records are not compared
|
||||
with the other nameservers', so no record change or inconsistency is reported
|
||||
for the type; on the next check they are compared with the nameserver's answer
|
||||
as usual. When the previous check did not know the type's records either,
|
||||
because the nameserver was new or failing then or the type was already listed
|
||||
in `unknownTypes`, the type is also listed in `unknownTypes` and left out of
|
||||
every comparison until it answers. A nameserver none of whose queries got a
|
||||
usable reply has failed (see NS query failure below).
|
||||
- Stores results **per nameserver**. The state for a hostname is not a merged
|
||||
view — it is a map from nameserver to record set.
|
||||
- DNS names inside record values (CNAME, MX, SRV and NS targets) are stored in
|
||||
@@ -125,8 +139,9 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
they keep disagreeing, including after a restart. A nameserver that was
|
||||
not in the previous check (newly added, or back after dropping out), or
|
||||
failed on it, and answers differently is reported on the check where it
|
||||
answers. If a pair agrees again and later disagrees, the alert is sent
|
||||
again.
|
||||
answers. So is a pair that differs in a record type whose query to either
|
||||
nameserver failed on the previous check. If a pair agrees again and later
|
||||
disagrees, the alert is sent again.
|
||||
- **CNAME address change**: The addresses at the end of a name's CNAME chain
|
||||
differ from those of the previous check. They are found when its
|
||||
nameservers answer with a CNAME and no address; a name that answers with
|
||||
@@ -545,7 +560,7 @@ reachability:
|
||||
|
||||
| Status | Meaning |
|
||||
| ------- | -------------------------------------------------------- |
|
||||
| `ok` | Query succeeded, records are current |
|
||||
| `ok` | Query succeeded, records are current except as below |
|
||||
| `error` | Query failed (timeout, SERVFAIL, REFUSED, network error) |
|
||||
|
||||
A nameserver that answers NXDOMAIN or with no records has status `ok` and empty
|
||||
@@ -554,6 +569,13 @@ nameservers, has status `error`, empty `records`, and the reason in `error`. A
|
||||
certificate entry whose TLS connection or handshake failed likewise has status
|
||||
`error`, the reason in `error`, and the certificate fields left empty or zero.
|
||||
|
||||
A nameserver with status `ok` whose query for one record type failed lists that
|
||||
type in `failedTypes` and holds its records from the previous check, which may
|
||||
not be current. When the previous check did not know the type's records either,
|
||||
because the nameserver was new or failing then or the type was already listed in
|
||||
`unknownTypes`, the type is also listed in `unknownTypes`, and `records` holds
|
||||
nothing for it. Both lists are left out when empty.
|
||||
|
||||
`nameserverAddresses` lists, by nameserver, the sorted addresses its name
|
||||
resolves to. A state file without it loads, and the next check fills it in
|
||||
without a notification.
|
||||
@@ -561,10 +583,10 @@ without a notification.
|
||||
`cnameAddresses` lists the sorted addresses at the end of the chain of every
|
||||
CNAME target a hostname's nameservers gave, found when they answered with a
|
||||
CNAME and no address; it is empty when they answered with an address. When a
|
||||
chain cannot be followed, or none of the name's nameservers answered, the
|
||||
previous check's list is kept, or `null` when no earlier check saved one. A
|
||||
state file without it loads, and the first check after that saves it without a
|
||||
notification.
|
||||
chain cannot be followed, or none of the name's nameservers answered its queries
|
||||
for A, AAAA and CNAME, the previous check's list is kept, or `null` when no
|
||||
earlier check saved one. A state file without it loads, and the first check
|
||||
after that saves it without a notification.
|
||||
|
||||
A port entry's `hostnames` lists every name that resolves to its address,
|
||||
domains included. A port entry in the older format, with one `hostname` instead
|
||||
|
||||
Reference in New Issue
Block a user