Replace the commit-pinned golangci-lint install refs in Dockerfile and
script/bootstrap with the v2.12.2 version pin, and replace .golangci.yml
with the canonical v2-schema config (lint settings now live under
linters.settings, so the lll/funlen/cyclop/dupl thresholds are actually
applied).
Fix all findings surfaced by the newly-applied config:
- goconst: introduce shared constants for repeated status, priority,
and DNS fixture strings in watcher.go and the notify, state, and
watcher tests
- dupl: consolidate duplicated ntfy/slack HTTP-error tests and
SendNotification endpoint-error tests behind shared helpers
- lll: wrap long test table entries and comments; shorten one inline
nolint justification
35 tests define the full resolver contract using live DNS queries
against *.dns.sneak.cloud (Cloudflare). Tests cover:
- FindAuthoritativeNameservers: iterative NS discovery, sorting,
determinism, trailing dot handling, TLD and subdomain cases
- QueryNameserver: A, AAAA, CNAME, MX, TXT, NXDOMAIN, per-NS
response model with status field, sorted record values
- QueryAllNameservers: independent per-NS queries, consistency
verification, NXDOMAIN from all NS
- LookupNS: NS record lookup matching FindAuthoritative
- ResolveIPAddresses: basic, multi-A, IPv6, dual-stack, CNAME
following, deduplication, sorting, NXDOMAIN returns empty
- Context cancellation for all methods
- Iterative resolution proof (resolves example.com from root)
Also adds DNSSEC validation to planned future features in README.
Full project structure following upaas conventions: uber/fx DI, go-chi
routing, slog logging, Viper config. State persisted as JSON file with
per-nameserver record tracking for inconsistency detection. Stub
implementations for resolver, portcheck, tlscheck, and watcher.