Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
251f05010f | ||
|
|
c9510a986c | ||
|
|
1f1640d4cd |
@@ -72,9 +72,8 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
- Every **1 hour** by default, performs a full iterative trace from root servers
|
||||
to discover all authoritative nameservers (NS records) for each domain.
|
||||
- Queries **every** discovered authoritative nameserver independently.
|
||||
- Stores the domain's NS record set, as the first of its own nameservers to
|
||||
answer returns it, and the IPv4 and IPv6 addresses each nameserver's name
|
||||
resolves to.
|
||||
- Stores the domain's NS record set, as its parent zone's servers delegate it,
|
||||
and the IPv4 and IPv6 addresses each nameserver's name resolves to.
|
||||
- Any change triggers a notification:
|
||||
- NS added to or removed from that set.
|
||||
- NS address change: a nameserver that stays in the set resolves to
|
||||
@@ -402,8 +401,8 @@ it watches. Instead, it performs full iterative resolution:
|
||||
built into the binary; the list is not refreshed.
|
||||
2. **TLD delegation**: Queries root servers for the TLD NS records.
|
||||
3. **Domain delegation**: Queries TLD nameservers for the domain's NS records.
|
||||
They refer it to the domain's own nameservers, and the first of those to
|
||||
answer gives the domain's NS record set.
|
||||
The delegation they give, from the domain's parent zone, is the domain's NS
|
||||
record set.
|
||||
4. **Authoritative query**: Queries all discovered authoritative nameservers
|
||||
directly for the requested records.
|
||||
|
||||
|
||||
@@ -21,6 +21,10 @@ trial run of the finished image: https://git.eeqj.de/sneak/dnswatcher/issues/149
|
||||
|
||||
- 2026-10-01: README checked against the code and corrected: metrics, CORS,
|
||||
notification retries, CNAMEs, state file fields, Design tree (closes #108).
|
||||
- 2026-10-01: a certificate within the expiry warning period is warned about on
|
||||
every TLS check, where some checks used to skip it at random (closes #204).
|
||||
- 2026-10-01: a domain's NS set is its delegation from the parent zone's
|
||||
servers, not whichever of its own servers answered first (closes #200).
|
||||
- 2026-10-01: README has Getting Started, Rationale and TODO sections, and its
|
||||
Architecture section is now Design, in the order policy sets (closes #173).
|
||||
- 2026-10-01: a zone's server that answers SERVFAIL or a referral leading no
|
||||
|
||||
@@ -16,6 +16,11 @@ func UsableReply(resp *dns.Msg, zone string, name string) bool {
|
||||
return usableReply(resp, zone, name)
|
||||
}
|
||||
|
||||
// NSSetFrom exports nsSetFrom for testing.
|
||||
func NSSetFrom(resp *dns.Msg, domain string) []string {
|
||||
return nsSetFrom(resp, domain)
|
||||
}
|
||||
|
||||
// CollectIPs exports collectIPs for testing.
|
||||
func CollectIPs(
|
||||
results map[string]*NameserverResponse,
|
||||
|
||||
@@ -222,9 +222,9 @@ func (r *Resolver) followDelegation(
|
||||
return nil, err
|
||||
}
|
||||
|
||||
ansNS := extractNSSet(resp.Answer)
|
||||
if len(ansNS) > 0 {
|
||||
return ansNS, nil
|
||||
nsSet := nsSetFrom(resp, domain)
|
||||
if len(nsSet) > 0 {
|
||||
return nsSet, nil
|
||||
}
|
||||
|
||||
// An authoritative reply comes from the servers of the zone
|
||||
@@ -325,6 +325,21 @@ func referralZone(resp *dns.Msg) string {
|
||||
return ""
|
||||
}
|
||||
|
||||
// nsSetFrom returns the NS set of domain that resp, a reply to a query
|
||||
// for domain's NS records, gives: the delegation in a referral to domain
|
||||
// itself, or else the NS records in the answer; empty when it gives
|
||||
// neither. A referral to domain comes from its parent zone's servers,
|
||||
// which all hold the same delegation, so the set does not depend on
|
||||
// which of them answered. domain's own servers, which can disagree about
|
||||
// their NS records, are then not asked.
|
||||
func nsSetFrom(resp *dns.Msg, domain string) []string {
|
||||
if referralZone(resp) == domain {
|
||||
return extractNSSet(resp.Ns)
|
||||
}
|
||||
|
||||
return extractNSSet(resp.Answer)
|
||||
}
|
||||
|
||||
func (r *Resolver) resolveNSIPs(
|
||||
ctx context.Context,
|
||||
nsNames []string,
|
||||
@@ -372,7 +387,7 @@ func (r *Resolver) resolveNSIterative(
|
||||
return nil, err
|
||||
}
|
||||
|
||||
nsNames := extractNSSet(resp.Answer)
|
||||
nsNames := nsSetFrom(resp, domain)
|
||||
if len(nsNames) > 0 {
|
||||
return nsNames, nil
|
||||
}
|
||||
@@ -465,7 +480,8 @@ func (r *Resolver) resolveARecord(
|
||||
|
||||
// FindAuthoritativeNameservers traces the delegation chain from
|
||||
// root servers to discover all authoritative nameservers for the
|
||||
// given domain. For a name that is not a zone apex it tries each
|
||||
// given domain, as the delegation from its parent zone's servers lists
|
||||
// them. For a name that is not a zone apex it tries each
|
||||
// parent name in turn, so it returns the nameservers of the zone the
|
||||
// name is in.
|
||||
func (r *Resolver) FindAuthoritativeNameservers(
|
||||
@@ -631,9 +647,10 @@ func (r *Resolver) querySingleType(
|
||||
|
||||
// A reply with no answer that lists other nameservers, from a server
|
||||
// that does not hold the name's zone, is a referral and says nothing
|
||||
// about the name's records. A parent zone's servers send one when
|
||||
// every server of the name's own zone failed and
|
||||
// FindAuthoritativeNameservers moved on to the parent name.
|
||||
// about the name's records. A server named in the delegation that
|
||||
// does not hold the zone may send one, as do a parent zone's servers
|
||||
// when FindAuthoritativeNameservers found no delegation for the
|
||||
// name's zone and moved on to a parent name.
|
||||
if !msg.Authoritative && len(msg.Answer) == 0 &&
|
||||
len(extractNSSet(msg.Ns)) > 0 {
|
||||
state.gotReferral = true
|
||||
|
||||
@@ -41,8 +41,15 @@ func TestCollectIPs_FailedIsNoAnswer(t *testing.T) {
|
||||
assert.Empty(t, ips)
|
||||
}
|
||||
|
||||
// exampleCom is the zone most cases of TestUsableReply are about.
|
||||
const exampleCom = "example.com."
|
||||
const (
|
||||
// exampleCom is the zone most cases of TestUsableReply and
|
||||
// TestNSSetFrom are about, and wwwExampleCom a name in it.
|
||||
exampleCom = "example.com."
|
||||
wwwExampleCom = "www.example.com."
|
||||
|
||||
// exampleNS is the server the NS records nsRecord builds name.
|
||||
exampleNS = "ns1.example.net."
|
||||
)
|
||||
|
||||
// nsRecord builds an NS record that names a server of zone.
|
||||
func nsRecord(zone string) *dns.NS {
|
||||
@@ -50,7 +57,7 @@ func nsRecord(zone string) *dns.NS {
|
||||
Hdr: dns.RR_Header{
|
||||
Name: zone, Rrtype: dns.TypeNS, Class: dns.ClassINET,
|
||||
},
|
||||
Ns: "ns1.example.net.",
|
||||
Ns: exampleNS,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -105,7 +112,7 @@ func TestUsableReply(t *testing.T) {
|
||||
},
|
||||
{
|
||||
name: "com refers to example.com", resp: referralTo(exampleCom),
|
||||
zone: "com.", query: "www.example.com.", want: true,
|
||||
zone: "com.", query: wwwExampleCom, want: true,
|
||||
},
|
||||
{
|
||||
name: "referral back to the zone", resp: referralTo(exampleCom),
|
||||
@@ -132,6 +139,51 @@ func TestUsableReply(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// TestNSSetFrom checks which NS set a reply gives for a domain; a set
|
||||
// that is not empty ends the walk. The referral to example.com that
|
||||
// com's servers all send alike gives its delegation, so the set is the
|
||||
// same whichever of them answered, and example.com's own servers, which
|
||||
// can disagree, are not asked.
|
||||
func TestNSSetFrom(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
answer := new(dns.Msg)
|
||||
answer.Authoritative = true
|
||||
answer.Answer = []dns.RR{nsRecord(exampleCom)}
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
resp *dns.Msg
|
||||
domain string
|
||||
want []string
|
||||
}{
|
||||
{
|
||||
name: "com refers to example.com", resp: referralTo(exampleCom),
|
||||
domain: exampleCom, want: []string{exampleNS},
|
||||
},
|
||||
{
|
||||
name: "com refers on, for www.example.com",
|
||||
resp: referralTo(exampleCom), domain: wwwExampleCom,
|
||||
want: nil,
|
||||
},
|
||||
{
|
||||
name: "answer from a server that holds example.com",
|
||||
resp: answer, domain: exampleCom,
|
||||
want: []string{exampleNS},
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
assert.ElementsMatch(t, tt.want,
|
||||
resolver.NSSetFrom(tt.resp, tt.domain),
|
||||
)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestExtractRecordValue_LetterCase(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
@@ -28,7 +28,6 @@ func NewForTest(
|
||||
tlsCheck: tc,
|
||||
notify: n,
|
||||
firstRun: true,
|
||||
expiryNotified: make(map[string]time.Time),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -72,6 +71,11 @@ func (w *Watcher) CheckAllPorts(ctx context.Context) {
|
||||
w.checkAllPorts(ctx)
|
||||
}
|
||||
|
||||
// RunTLSChecks exports runTLSChecks for testing.
|
||||
func (w *Watcher) RunTLSChecks(ctx context.Context) {
|
||||
w.runTLSChecks(ctx)
|
||||
}
|
||||
|
||||
// BuildHostnameState exports buildHostnameState for testing.
|
||||
func BuildHostnameState(
|
||||
results map[string]*resolver.NameserverResponse,
|
||||
|
||||
@@ -7,7 +7,6 @@ import (
|
||||
"slices"
|
||||
"sort"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
@@ -59,8 +58,6 @@ type Watcher struct {
|
||||
cancel context.CancelFunc
|
||||
done chan struct{} // closed when Run returns
|
||||
firstRun bool
|
||||
expiryNotifiedMu sync.Mutex
|
||||
expiryNotified map[string]time.Time
|
||||
}
|
||||
|
||||
// New creates a new Watcher instance wired into the fx lifecycle.
|
||||
@@ -77,7 +74,6 @@ func New(
|
||||
tlsCheck: params.TLSCheck,
|
||||
notify: params.Notify,
|
||||
firstRun: true,
|
||||
expiryNotified: make(map[string]time.Time),
|
||||
}
|
||||
|
||||
lifecycle.Append(fx.Hook{
|
||||
@@ -1028,22 +1024,6 @@ func (w *Watcher) checkTLSExpiry(
|
||||
return
|
||||
}
|
||||
|
||||
// Deduplicate expiry warnings: don't re-notify for the same
|
||||
// hostname within the TLS check interval.
|
||||
dedupKey := fmt.Sprintf("expiry:%s:%s", hostname, ip)
|
||||
|
||||
w.expiryNotifiedMu.Lock()
|
||||
|
||||
lastNotified, seen := w.expiryNotified[dedupKey]
|
||||
if seen && time.Since(lastNotified) < w.config.TLSInterval {
|
||||
w.expiryNotifiedMu.Unlock()
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
w.expiryNotified[dedupKey] = time.Now()
|
||||
w.expiryNotifiedMu.Unlock()
|
||||
|
||||
msg := fmt.Sprintf(
|
||||
"Host: %s\nIP: %s\nCN: %s\n"+
|
||||
"Expires: %s (%.0f days)",
|
||||
|
||||
@@ -615,34 +615,55 @@ func TestTLSExpiryWarning(t *testing.T) {
|
||||
assertNotified(t, deps, "TLS Expiry Warning: "+testHost, "warning")
|
||||
}
|
||||
|
||||
func TestTLSExpiryWarningDedup(t *testing.T) {
|
||||
// TestTLSExpiryWarningEachCheck runs the TLS checks three times in a
|
||||
// row on hostname and port state built here, for a certificate that
|
||||
// expires within the warning period. Each check warns once, whether the
|
||||
// TLS interval is a nanosecond, shorter than the time between two
|
||||
// checks, or a day, longer than it.
|
||||
func TestTLSExpiryWarningEachCheck(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
title := "TLS Expiry Warning: " + host
|
||||
|
||||
for _, interval := range []time.Duration{time.Nanosecond, 24 * time.Hour} {
|
||||
t.Run(interval.String(), func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Hostnames = []string{testHost}
|
||||
cfg.TLSInterval = 24 * time.Hour
|
||||
cfg.Hostnames = []string{host}
|
||||
cfg.TLSInterval = interval
|
||||
|
||||
title := "TLS Expiry Warning: " + testHost
|
||||
// The TLS checks read the saved hostname and port state and
|
||||
// look nothing up, so the watcher has no resolver.
|
||||
deps := newTestDeps(t, cfg)
|
||||
w := watcher.NewForTest(
|
||||
cfg, deps.state, nil,
|
||||
deps.portChecker, deps.tlsChecker, deps.notifier,
|
||||
)
|
||||
|
||||
// The second check comes within the TLS interval of the first,
|
||||
// so it must not warn again.
|
||||
var warnings int
|
||||
|
||||
deps := runChecks(t, cfg, expiresInThreeDays, func(deps *testDeps) {
|
||||
warnings = countNotifications(deps, title)
|
||||
expiresInThreeDays(deps)
|
||||
deps.state.SetHostnameState(host, saved(
|
||||
map[string]*state.NameserverRecordState{
|
||||
nsA: answered(map[string][]string{"A": {ip1}}),
|
||||
},
|
||||
))
|
||||
deps.state.SetPortState(ip1+":443", &state.PortState{
|
||||
Open: true, Hostnames: []string{host},
|
||||
})
|
||||
|
||||
if warnings == 0 {
|
||||
t.Fatal("expected expiry warnings from the first check")
|
||||
}
|
||||
for check := 1; check <= 3; check++ {
|
||||
w.RunTLSChecks(t.Context())
|
||||
|
||||
got := countNotifications(deps, title)
|
||||
if got != warnings {
|
||||
t.Errorf(
|
||||
"expected %d expiry warnings (dedup), got %d",
|
||||
warnings, got,
|
||||
if got != check {
|
||||
t.Fatalf(
|
||||
"after check %d: %d expiry warnings, want %d",
|
||||
check, got, check,
|
||||
)
|
||||
}
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestGracefulShutdown(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user