Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a771f51b0b | ||
|
|
9bd1a71d8f |
@@ -21,6 +21,8 @@ trial run of the finished image: https://git.eeqj.de/sneak/dnswatcher/issues/149
|
||||
|
||||
- 2026-10-02: a domain that does not exist is shown so, with no nameservers; no
|
||||
name gets a parent's nameservers when its own did not answer (closes #222).
|
||||
- 2026-10-02: the refused-query test sends one query to four operators' public
|
||||
resolvers in turn until one replies, not eight to one operator (closes #251).
|
||||
- 2026-10-02: a name removed from `DNSWATCHER_TARGETS` leaves the state, and so
|
||||
the dashboard and API, at startup, before the first check (closes #223).
|
||||
- 2026-10-02: a record type whose query to a nameserver fails keeps its previous
|
||||
|
||||
@@ -490,48 +490,45 @@ func TestQueryNameserver_Refused(t *testing.T) {
|
||||
assert.Equal(t, "server returned REFUSED", resp.Error)
|
||||
}
|
||||
|
||||
// TestQueryNameserverIP_RecursiveResolverRefused asks Quad9, a public
|
||||
// recursive resolver, about google.com at both of its addresses. Quad9
|
||||
// refuses a query that does not ask for recursion and answers one that
|
||||
// does. The resolver never asks for recursion, so it must be reported
|
||||
// as refusing, never as answering.
|
||||
func TestQueryNameserverIP_RecursiveResolverRefused(t *testing.T) {
|
||||
// TestQueryServers_RecursiveResolverRefused passes a public recursive
|
||||
// resolver to QueryServers as the server of google.com. These resolvers
|
||||
// refuse a query that does not ask for recursion and answer one that
|
||||
// does. The resolver never asks for recursion, so the query must be
|
||||
// reported as refused, never answered. Each resolver is run by a
|
||||
// different operator, and they are asked in turn until one replies, so
|
||||
// one operator not answering does not fail the test.
|
||||
func TestQueryServers_RecursiveResolverRefused(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
r := newTestResolver(t)
|
||||
|
||||
for _, ip := range []string{"9.9.9.9", "149.112.112.112"} {
|
||||
var resp *resolver.NameserverResponse
|
||||
|
||||
livednstest.Retry(
|
||||
t,
|
||||
"QueryNameserverIP("+ip+", google.com)",
|
||||
func(ctx context.Context) error {
|
||||
var err error
|
||||
|
||||
resp, err = r.QueryNameserverIP(
|
||||
ctx, ip, ip, "google.com",
|
||||
)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// A timeout or a network error is no reply at all.
|
||||
if resp.Status == resolver.StatusTimeout ||
|
||||
strings.HasPrefix(resp.Error, "network error") {
|
||||
return fmt.Errorf(
|
||||
"%w: %s: %s",
|
||||
livednstest.ErrNoAnswer, ip, resp.Error,
|
||||
)
|
||||
}
|
||||
|
||||
return nil
|
||||
},
|
||||
)
|
||||
|
||||
assert.Equal(t, resolver.StatusError, resp.Status, ip)
|
||||
assert.Equal(t, "server returned REFUSED", resp.Error, ip)
|
||||
resolvers := []string{
|
||||
"64.6.64.6", "185.222.222.222", "4.2.2.1", "9.9.9.9",
|
||||
}
|
||||
|
||||
var err error
|
||||
|
||||
livednstest.Retry(
|
||||
t,
|
||||
"QueryServers(public recursive resolvers, google.com)",
|
||||
func(ctx context.Context) error {
|
||||
for _, ip := range resolvers {
|
||||
_, err = r.QueryServers(
|
||||
ctx, []string{ip}, "google.com.", "google.com.",
|
||||
dns.TypeA,
|
||||
)
|
||||
|
||||
// A refusal or an answer is a reply; anything else may
|
||||
// be no reply at all, so the next resolver is asked.
|
||||
if err == nil || errors.Is(err, resolver.ErrRefused) {
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
return fmt.Errorf("%w: %w", livednstest.ErrNoAnswer, err)
|
||||
},
|
||||
)
|
||||
|
||||
require.ErrorIs(t, err, resolver.ErrRefused)
|
||||
}
|
||||
|
||||
// googleNameserverIPv4s returns the IPv4 addresses of google.com's
|
||||
|
||||
@@ -551,6 +551,50 @@ func TestDomainThatDoesNotExist(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// TestDomainWithNoDelegationOfItsOwn checks a domain with no delegation
|
||||
// of its own: codeberg.page is on the public suffix list, so
|
||||
// docs.codeberg.page is a domain, but the .page servers delegate only
|
||||
// codeberg.page, whose servers answer for it. It is saved with no
|
||||
// nameservers and without nxdomain, and its records, asked at the
|
||||
// codeberg.page servers, are saved. Those are testSmallDomain's two
|
||||
// nameservers; github.io, the zone of the README's example, has eight.
|
||||
func TestDomainWithNoDelegationOfItsOwn(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
const domain = "docs.codeberg.page"
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{domain}
|
||||
|
||||
var deps *testDeps
|
||||
|
||||
livednstest.Retry(t, "watcher checks", func(ctx context.Context) error {
|
||||
var w *watcher.Watcher
|
||||
|
||||
w, deps = newTestWatcher(t, cfg)
|
||||
|
||||
err := checkOnce(ctx, w, deps)
|
||||
|
||||
// A domain saved as not existing has no records to wait for;
|
||||
// the checks below fail on it.
|
||||
if ds, ok := deps.state.GetDomainState(domain); ok && ds.NXDomain {
|
||||
return nil
|
||||
}
|
||||
|
||||
return err
|
||||
})
|
||||
|
||||
ds, _ := deps.state.GetDomainState(domain)
|
||||
if ds.NXDomain || len(ds.Nameservers) != 0 {
|
||||
t.Errorf("saved nxdomain %v and nameservers %v, want false and none",
|
||||
ds.NXDomain, ds.Nameservers)
|
||||
}
|
||||
|
||||
if _, ok := deps.state.GetHostnameState(domain); !ok {
|
||||
t.Errorf("no records saved for %s", domain)
|
||||
}
|
||||
}
|
||||
|
||||
func TestNSAddressChangeDetection(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user