Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3baead677c |
@@ -12,47 +12,40 @@ import (
|
|||||||
"sneak.berlin/go/dnswatcher/internal/watcher"
|
"sneak.berlin/go/dnswatcher/internal/watcher"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Each name these tests look up in live DNS, and each zone a CNAME
|
// TestCNAMEIntoAnotherZonePortAndTLSChecks runs the port and TLS
|
||||||
// points into, has two nameservers, to keep queries few (see the top
|
// checks on hostname state built here: the name's nameserver answered
|
||||||
// of watcher_test.go). cnameHost is a CNAME into another zone,
|
// with a CNAME into another zone, and following it found ip1. Both
|
||||||
// readthedocs.io: its nameservers answer with the CNAME and no address.
|
// checks must use ip1. They look nothing up, so the watcher has no
|
||||||
const cnameHost = "flask.palletsprojects.com"
|
// resolver.
|
||||||
|
|
||||||
// TestCNAMEIntoAnotherZonePortAndTLSChecks checks cnameHost against
|
|
||||||
// live DNS. Its port and TLS checks must use the addresses at the end
|
|
||||||
// of its CNAME chain.
|
|
||||||
func TestCNAMEIntoAnotherZonePortAndTLSChecks(t *testing.T) {
|
func TestCNAMEIntoAnotherZonePortAndTLSChecks(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
cfg := defaultTestConfig(t)
|
cfg := defaultTestConfig(t)
|
||||||
cfg.Hostnames = []string{cnameHost}
|
cfg.Hostnames = []string{host}
|
||||||
|
|
||||||
_, deps := runChecks(t, cfg, nil)
|
deps := newTestDeps(t, cfg)
|
||||||
|
w := watcher.NewForTest(
|
||||||
|
cfg, deps.state, nil,
|
||||||
|
deps.portChecker, deps.tlsChecker, deps.notifier,
|
||||||
|
)
|
||||||
|
|
||||||
|
deps.state.SetHostnameState(host, cnameState(ip1))
|
||||||
|
|
||||||
|
w.CheckAllPorts(t.Context())
|
||||||
|
w.RunTLSChecks(t.Context())
|
||||||
|
|
||||||
snap := deps.state.GetSnapshot()
|
snap := deps.state.GetSnapshot()
|
||||||
hs := snap.Hostnames[cnameHost]
|
|
||||||
|
|
||||||
if len(hs.CNAMEAddresses) == 0 {
|
ps, ok := snap.Ports[ip1+":443"]
|
||||||
t.Fatalf(
|
if !ok || !slices.Contains(ps.Hostnames, host) {
|
||||||
"%s: no addresses saved from following its CNAME; if it "+
|
t.Errorf("no port state for %s at %s:443", host, ip1)
|
||||||
"is no longer a CNAME into another zone, this test "+
|
|
||||||
"needs another name",
|
|
||||||
cnameHost,
|
|
||||||
)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, ip := range hs.CNAMEAddresses {
|
certKey := ip1 + ":443:" + host
|
||||||
ps, ok := snap.Ports[ip+":443"]
|
|
||||||
if !ok || !slices.Contains(ps.Hostnames, cnameHost) {
|
|
||||||
t.Errorf("no port state for %s at %s:443", cnameHost, ip)
|
|
||||||
}
|
|
||||||
|
|
||||||
certKey := ip + ":443:" + cnameHost
|
|
||||||
if _, ok := snap.Certificates[certKey]; !ok {
|
if _, ok := snap.Certificates[certKey]; !ok {
|
||||||
t.Errorf("no certificate state %s", certKey)
|
t.Errorf("no certificate state %s", certKey)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// TestCNAMEThatCannotBeFollowedKeepsPrevious gives a name a CNAME to a
|
// TestCNAMEThatCannotBeFollowedKeepsPrevious gives a name a CNAME to a
|
||||||
// target under .invalid, whose lookup fails. The addresses the previous
|
// target under .invalid, whose lookup fails. The addresses the previous
|
||||||
@@ -88,7 +81,9 @@ func TestCNAMEThatCannotBeFollowedKeepsPrevious(t *testing.T) {
|
|||||||
// followLive follows in live DNS the CNAMEs in a name's records, built
|
// followLive follows in live DNS the CNAMEs in a name's records, built
|
||||||
// from records, and returns the addresses saved for the name. The
|
// from records, and returns the addresses saved for the name. The
|
||||||
// previous check saved oldIP, which is kept when a target cannot be
|
// previous check saved oldIP, which is kept when a target cannot be
|
||||||
// followed; that is retried.
|
// followed; that is retried. The tests point CNAMEs only at names in
|
||||||
|
// zones with two nameservers, to keep queries few (see the top of
|
||||||
|
// watcher_test.go).
|
||||||
func followLive(
|
func followLive(
|
||||||
t *testing.T,
|
t *testing.T,
|
||||||
records map[string]map[string][]string,
|
records map[string]map[string][]string,
|
||||||
|
|||||||
@@ -372,6 +372,14 @@ func TestFirstRunBaseline(t *testing.T) {
|
|||||||
|
|
||||||
assertNoNotifications(t, deps)
|
assertNoNotifications(t, deps)
|
||||||
assertStatePopulated(t, deps)
|
assertStatePopulated(t, deps)
|
||||||
|
|
||||||
|
// testHost answers with an address, so the check saves an empty list
|
||||||
|
// of CNAME addresses for it; nil would mean the check did not look
|
||||||
|
// at whether to follow a CNAME.
|
||||||
|
hs, _ := deps.state.GetHostnameState(testHost)
|
||||||
|
if hs.CNAMEAddresses == nil || len(hs.CNAMEAddresses) != 0 {
|
||||||
|
t.Errorf("saved CNAME addresses %#v, want []", hs.CNAMEAddresses)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func assertNoNotifications(
|
func assertNoNotifications(
|
||||||
|
|||||||
Reference in New Issue
Block a user