Compare commits
4 Commits
feature/re
...
fix/106-no
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cd06bba034 | ||
|
|
970ea9fae8 | ||
| 9347a2838b | |||
| f79cd98107 |
@@ -1,5 +1,9 @@
|
||||
version: "2"
|
||||
|
||||
# Config schema uses the golangci-lint v2 layout (settings live under
|
||||
# linters.settings, not top-level linters-settings) so that the
|
||||
# thresholds below are actually applied by golangci-lint >= v2.
|
||||
|
||||
run:
|
||||
timeout: 5m
|
||||
modules-download-mode: readonly
|
||||
@@ -14,19 +18,17 @@ linters:
|
||||
- wsl # Deprecated, replaced by wsl_v5
|
||||
- wrapcheck # Too verbose for internal packages
|
||||
- varnamelen # Short names like db, id are idiomatic Go
|
||||
|
||||
linters-settings:
|
||||
lll:
|
||||
line-length: 88
|
||||
funlen:
|
||||
lines: 80
|
||||
statements: 50
|
||||
cyclop:
|
||||
max-complexity: 15
|
||||
dupl:
|
||||
threshold: 100
|
||||
settings:
|
||||
lll:
|
||||
line-length: 88
|
||||
funlen:
|
||||
lines: 80
|
||||
statements: 50
|
||||
cyclop:
|
||||
max-complexity: 15
|
||||
dupl:
|
||||
threshold: 100
|
||||
|
||||
issues:
|
||||
exclude-use-default: false
|
||||
max-issues-per-linter: 0
|
||||
max-same-issues: 0
|
||||
|
||||
@@ -4,8 +4,8 @@ FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4
|
||||
|
||||
RUN apk add --no-cache git make gcc musl-dev binutils-gold
|
||||
|
||||
# golangci-lint v2.10.1
|
||||
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@5d1e709b7be35cb2025444e19de266b056b7b7ee
|
||||
# golangci-lint v2.12.2, 2026-08-07
|
||||
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5
|
||||
# goimports v0.42.0
|
||||
RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0
|
||||
|
||||
|
||||
33
README.md
33
README.md
@@ -17,6 +17,26 @@ without requiring an external database.
|
||||
|
||||
---
|
||||
|
||||
## No DNS mocking. Ever.
|
||||
|
||||
**DNS is never mocked in this project — not in tests, not anywhere else.**
|
||||
No mock resolvers, no fake DNS servers, no stubbed lookups.
|
||||
|
||||
dnswatcher's entire purpose is correct behavior against the real DNS.
|
||||
Tests exercise real iterative resolution against live nameservers by
|
||||
design; a test suite that passes against a mock proves nothing about the
|
||||
one thing this program exists to do.
|
||||
|
||||
When live tests are flaky, that is a robustness problem, and it gets
|
||||
fixed with robustness: retries with backoff, querying multiple
|
||||
independent nameservers, longer timeouts — or explicit opt-in gating
|
||||
decided by the project owner. Never with mocks.
|
||||
|
||||
Contributions that introduce mocked, faked, or stubbed DNS will be
|
||||
rejected.
|
||||
|
||||
---
|
||||
|
||||
## Features
|
||||
|
||||
### DNS Domain Monitoring (Apex Domains)
|
||||
@@ -198,7 +218,8 @@ internal/
|
||||
- **Structured logging**: All logs use `log/slog` with JSON output in
|
||||
production (TTY detection for development).
|
||||
- **Graceful shutdown**: All background goroutines respect context
|
||||
cancellation and the fx lifecycle.
|
||||
cancellation and the fx lifecycle. In-flight notification deliveries
|
||||
are drained on shutdown, bounded by the shutdown timeout.
|
||||
|
||||
---
|
||||
|
||||
@@ -432,8 +453,14 @@ docker run -d \
|
||||
from a previous cycle.
|
||||
4. **On change detection**: Send notifications to all configured
|
||||
endpoints, update in-memory state, persist to disk.
|
||||
5. **Shutdown**: Persist final state to disk, complete in-flight
|
||||
notifications, stop gracefully.
|
||||
5. **Shutdown**: Persist final state to disk, wait for in-flight
|
||||
notification deliveries to complete, stop gracefully. The wait is
|
||||
bounded by the fx shutdown timeout (15s by default): deliveries still
|
||||
retrying against an unreachable endpoint when that expires are
|
||||
abandoned, and the number abandoned is logged at warn level rather
|
||||
than dropped silently. Notifications generated after shutdown has
|
||||
begun are refused and logged, so a late burst cannot extend the
|
||||
shutdown.
|
||||
|
||||
---
|
||||
|
||||
|
||||
17
TODO.md
17
TODO.md
@@ -25,6 +25,23 @@ confirm make check still passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-09: in-flight notification deliveries are now drained at
|
||||
shutdown (#106): `notify.New` registers an fx `OnStop` hook that waits
|
||||
on a `sync.WaitGroup` of tracked delivery goroutines, bounded by the
|
||||
`OnStop` context; on expiry the outstanding count is logged at warn
|
||||
level and parked retry backoffs are released instead of being dropped
|
||||
silently, and deliveries submitted after the drain begins are refused
|
||||
so shutdown cannot be extended indefinitely; an `OnStop` context that
|
||||
is already expired on entry with nothing outstanding drains quietly
|
||||
rather than warning about deliveries that were never abandoned
|
||||
- 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs
|
||||
in `Dockerfile` and `script/bootstrap`); `.golangci.yml` set to the
|
||||
org-standard v2-schema config used across the org's repos
|
||||
(owner-authorized; same file is being landed as canonical via prompts
|
||||
PR #24), with settings under `linters.settings` so the
|
||||
lll/funlen/cyclop/dupl thresholds apply; fixed the resulting
|
||||
`goconst`, `dupl`, and `lll` findings; the informational `gomodguard`
|
||||
deprecation warning under this config is accepted
|
||||
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
|
||||
Makefile shims, README Entrypoints section
|
||||
- 2026-02-20: iterative DNS resolver implemented; tests made hermetic
|
||||
|
||||
@@ -17,13 +17,33 @@ func TestClassifyDNSName(t *testing.T) {
|
||||
}{
|
||||
{name: "apex domain simple", input: "example.com", want: config.DNSNameTypeDomain},
|
||||
{name: "hostname simple", input: "www.example.com", want: config.DNSNameTypeHostname},
|
||||
{name: "apex domain multi-part TLD", input: "example.co.uk", want: config.DNSNameTypeDomain},
|
||||
{name: "hostname multi-part TLD", input: "api.example.co.uk", want: config.DNSNameTypeHostname},
|
||||
{
|
||||
name: "apex domain multi-part TLD",
|
||||
input: "example.co.uk",
|
||||
want: config.DNSNameTypeDomain,
|
||||
},
|
||||
{
|
||||
name: "hostname multi-part TLD",
|
||||
input: "api.example.co.uk",
|
||||
want: config.DNSNameTypeHostname,
|
||||
},
|
||||
{name: "public suffix itself", input: "co.uk", wantErr: true},
|
||||
{name: "empty string", input: "", wantErr: true},
|
||||
{name: "deeply nested hostname", input: "a.b.c.example.com", want: config.DNSNameTypeHostname},
|
||||
{name: "trailing dot stripped", input: "example.com.", want: config.DNSNameTypeDomain},
|
||||
{name: "uppercase normalized", input: "WWW.Example.COM", want: config.DNSNameTypeHostname},
|
||||
{
|
||||
name: "deeply nested hostname",
|
||||
input: "a.b.c.example.com",
|
||||
want: config.DNSNameTypeHostname,
|
||||
},
|
||||
{
|
||||
name: "trailing dot stripped",
|
||||
input: "example.com.",
|
||||
want: config.DNSNameTypeDomain,
|
||||
},
|
||||
{
|
||||
name: "uppercase normalized",
|
||||
input: "WWW.Example.COM",
|
||||
want: config.DNSNameTypeHostname,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
|
||||
@@ -25,6 +25,20 @@ const (
|
||||
colorDefault = "#6c757d"
|
||||
)
|
||||
|
||||
// Priority strings used across multiple tests.
|
||||
const (
|
||||
prioError = "error"
|
||||
prioWarning = "warning"
|
||||
prioSuccess = "success"
|
||||
prioInfo = "info"
|
||||
prioUnknown = "unknown"
|
||||
prioDefault = "default"
|
||||
prioUrgent = "urgent"
|
||||
)
|
||||
|
||||
// testHost is the hostname used in request construction tests.
|
||||
const testHost = "example.com"
|
||||
|
||||
// errSimulated is a static error for transport failures.
|
||||
var errSimulated = errors.New("simulated transport failure")
|
||||
|
||||
@@ -101,13 +115,13 @@ func TestNtfyPriority(t *testing.T) {
|
||||
input string
|
||||
want string
|
||||
}{
|
||||
{"error", "urgent"},
|
||||
{"warning", "high"},
|
||||
{"success", "default"},
|
||||
{"info", "low"},
|
||||
{"", "default"},
|
||||
{"unknown", "default"},
|
||||
{"critical", "default"},
|
||||
{prioError, prioUrgent},
|
||||
{prioWarning, "high"},
|
||||
{prioSuccess, prioDefault},
|
||||
{prioInfo, "low"},
|
||||
{"", prioDefault},
|
||||
{prioUnknown, prioDefault},
|
||||
{"critical", prioDefault},
|
||||
}
|
||||
|
||||
for _, tc := range cases {
|
||||
@@ -134,12 +148,12 @@ func TestSlackColor(t *testing.T) {
|
||||
input string
|
||||
want string
|
||||
}{
|
||||
{"error", colorError},
|
||||
{"warning", colorWarning},
|
||||
{"success", colorSuccess},
|
||||
{"info", colorInfo},
|
||||
{prioError, colorError},
|
||||
{prioWarning, colorWarning},
|
||||
{prioSuccess, colorSuccess},
|
||||
{prioInfo, colorInfo},
|
||||
{"", colorDefault},
|
||||
{"unknown", colorDefault},
|
||||
{prioUnknown, colorDefault},
|
||||
{"critical", colorDefault},
|
||||
}
|
||||
|
||||
@@ -165,7 +179,7 @@ func TestNewRequest(t *testing.T) {
|
||||
|
||||
target := &url.URL{
|
||||
Scheme: "https",
|
||||
Host: "example.com",
|
||||
Host: testHost,
|
||||
Path: "/webhook",
|
||||
}
|
||||
body := bytes.NewBufferString("hello")
|
||||
@@ -187,9 +201,9 @@ func TestNewRequest(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
if req.Host != "example.com" {
|
||||
if req.Host != testHost {
|
||||
t.Errorf(
|
||||
"Host = %q, want %q", req.Host, "example.com",
|
||||
"Host = %q, want %q", req.Host, testHost,
|
||||
)
|
||||
}
|
||||
|
||||
@@ -217,7 +231,7 @@ func TestNewRequestPreservesContext(t *testing.T) {
|
||||
ctxKey("k"),
|
||||
"v",
|
||||
)
|
||||
target := &url.URL{Scheme: "https", Host: "example.com"}
|
||||
target := &url.URL{Scheme: "https", Host: testHost}
|
||||
|
||||
req := notify.NewRequestForTest(
|
||||
ctx, http.MethodGet, target, http.NoBody,
|
||||
@@ -289,10 +303,10 @@ func TestSendNtfyHeaders(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
if captured.priority != "urgent" {
|
||||
if captured.priority != prioUrgent {
|
||||
t.Errorf(
|
||||
"Priority header = %q, want %q",
|
||||
captured.priority, "urgent",
|
||||
captured.priority, prioUrgent,
|
||||
)
|
||||
}
|
||||
|
||||
@@ -311,10 +325,10 @@ func TestSendNtfyAllPriorities(t *testing.T) {
|
||||
input string
|
||||
want string
|
||||
}{
|
||||
{"error", "urgent"},
|
||||
{"warning", "high"},
|
||||
{"success", "default"},
|
||||
{"info", "low"},
|
||||
{prioError, prioUrgent},
|
||||
{prioWarning, "high"},
|
||||
{prioSuccess, prioDefault},
|
||||
{prioInfo, "low"},
|
||||
}
|
||||
|
||||
for _, tc := range priorities {
|
||||
@@ -356,56 +370,69 @@ func TestSendNtfyAllPriorities(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestSendNtfyClientError(t *testing.T) {
|
||||
t.Parallel()
|
||||
// assertSendStatusError verifies that send returns an error
|
||||
// wrapping wantErr when the server responds with status.
|
||||
func assertSendStatusError(
|
||||
t *testing.T,
|
||||
status int,
|
||||
wantErr error,
|
||||
send func(*notify.Service, *url.URL) error,
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusForbidden)
|
||||
w.WriteHeader(status)
|
||||
}),
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
svc := notify.NewTestService(srv.Client().Transport)
|
||||
topicURL, _ := url.Parse(srv.URL)
|
||||
target, _ := url.Parse(srv.URL)
|
||||
|
||||
err := svc.SendNtfy(
|
||||
context.Background(), topicURL, "t", "m", "info",
|
||||
)
|
||||
err := send(svc, target)
|
||||
if err == nil {
|
||||
t.Fatal("expected error for 403 response")
|
||||
t.Fatalf("expected error for %d response", status)
|
||||
}
|
||||
|
||||
if !errors.Is(err, notify.ErrNtfyFailed) {
|
||||
t.Errorf("error = %v, want ErrNtfyFailed", err)
|
||||
if !errors.Is(err, wantErr) {
|
||||
t.Errorf("error = %v, want %v", err, wantErr)
|
||||
}
|
||||
}
|
||||
|
||||
func sendNtfyInfo(
|
||||
svc *notify.Service, target *url.URL,
|
||||
) error {
|
||||
return svc.SendNtfy(
|
||||
context.Background(), target, "t", "m", prioInfo,
|
||||
)
|
||||
}
|
||||
|
||||
func sendSlackInfo(
|
||||
svc *notify.Service, target *url.URL,
|
||||
) error {
|
||||
return svc.SendSlack(
|
||||
context.Background(), target, "t", "m", prioInfo,
|
||||
)
|
||||
}
|
||||
|
||||
func TestSendNtfyClientError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
assertSendStatusError(
|
||||
t, http.StatusForbidden,
|
||||
notify.ErrNtfyFailed, sendNtfyInfo,
|
||||
)
|
||||
}
|
||||
|
||||
func TestSendNtfyServerError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusInternalServerError)
|
||||
}),
|
||||
assertSendStatusError(
|
||||
t, http.StatusInternalServerError,
|
||||
notify.ErrNtfyFailed, sendNtfyInfo,
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
svc := notify.NewTestService(srv.Client().Transport)
|
||||
topicURL, _ := url.Parse(srv.URL)
|
||||
|
||||
err := svc.SendNtfy(
|
||||
context.Background(), topicURL, "t", "m", "info",
|
||||
)
|
||||
if err == nil {
|
||||
t.Fatal("expected error for 500 response")
|
||||
}
|
||||
|
||||
if !errors.Is(err, notify.ErrNtfyFailed) {
|
||||
t.Errorf("error = %v, want ErrNtfyFailed", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSendNtfySuccess(t *testing.T) {
|
||||
@@ -550,11 +577,11 @@ func TestSendSlackAllColors(t *testing.T) {
|
||||
priority string
|
||||
want string
|
||||
}{
|
||||
{"error", colorError},
|
||||
{"warning", colorWarning},
|
||||
{"success", colorSuccess},
|
||||
{"info", colorInfo},
|
||||
{"unknown", colorDefault},
|
||||
{prioError, colorError},
|
||||
{prioWarning, colorWarning},
|
||||
{prioSuccess, colorSuccess},
|
||||
{prioInfo, colorInfo},
|
||||
{prioUnknown, colorDefault},
|
||||
}
|
||||
|
||||
for _, tc := range colors {
|
||||
@@ -606,53 +633,19 @@ func TestSendSlackAllColors(t *testing.T) {
|
||||
func TestSendSlackClientError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusBadRequest)
|
||||
}),
|
||||
assertSendStatusError(
|
||||
t, http.StatusBadRequest,
|
||||
notify.ErrSlackFailed, sendSlackInfo,
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
svc := notify.NewTestService(srv.Client().Transport)
|
||||
webhookURL, _ := url.Parse(srv.URL)
|
||||
|
||||
err := svc.SendSlack(
|
||||
context.Background(), webhookURL, "t", "m", "info",
|
||||
)
|
||||
if err == nil {
|
||||
t.Fatal("expected error for 400 response")
|
||||
}
|
||||
|
||||
if !errors.Is(err, notify.ErrSlackFailed) {
|
||||
t.Errorf("error = %v, want ErrSlackFailed", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSendSlackServerError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusBadGateway)
|
||||
}),
|
||||
assertSendStatusError(
|
||||
t, http.StatusBadGateway,
|
||||
notify.ErrSlackFailed, sendSlackInfo,
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
svc := notify.NewTestService(srv.Client().Transport)
|
||||
webhookURL, _ := url.Parse(srv.URL)
|
||||
|
||||
err := svc.SendSlack(
|
||||
context.Background(), webhookURL, "t", "m", "error",
|
||||
)
|
||||
if err == nil {
|
||||
t.Fatal("expected error for 502 response")
|
||||
}
|
||||
|
||||
if !errors.Is(err, notify.ErrSlackFailed) {
|
||||
t.Errorf("error = %v, want ErrSlackFailed", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSendSlackNetworkError(t *testing.T) {
|
||||
@@ -977,74 +970,62 @@ func TestSendNotificationMattermostOnly(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestSendNotificationNtfyError(t *testing.T) {
|
||||
t.Parallel()
|
||||
// assertSendNotificationTolerates verifies SendNotification
|
||||
// neither panics nor blocks when the endpoint configured by
|
||||
// setURL responds with status.
|
||||
func assertSendNotificationTolerates(
|
||||
t *testing.T,
|
||||
status int,
|
||||
priority string,
|
||||
setURL func(*notify.Service, *url.URL),
|
||||
) {
|
||||
t.Helper()
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusInternalServerError)
|
||||
w.WriteHeader(status)
|
||||
}),
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
ntfyURL, _ := url.Parse(srv.URL)
|
||||
target, _ := url.Parse(srv.URL)
|
||||
|
||||
svc := notify.NewTestService(http.DefaultTransport)
|
||||
svc.SetNtfyURL(ntfyURL)
|
||||
setURL(svc, target)
|
||||
|
||||
// Should not panic or block.
|
||||
svc.SendNotification(
|
||||
context.Background(), "t", "m", "error",
|
||||
context.Background(), "t", "m", priority,
|
||||
)
|
||||
|
||||
time.Sleep(100 * time.Millisecond)
|
||||
}
|
||||
|
||||
func TestSendNotificationNtfyError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
assertSendNotificationTolerates(
|
||||
t, http.StatusInternalServerError, prioError,
|
||||
(*notify.Service).SetNtfyURL,
|
||||
)
|
||||
}
|
||||
|
||||
func TestSendNotificationSlackError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusForbidden)
|
||||
}),
|
||||
assertSendNotificationTolerates(
|
||||
t, http.StatusForbidden, prioError,
|
||||
(*notify.Service).SetSlackWebhookURL,
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
slackURL, _ := url.Parse(srv.URL)
|
||||
|
||||
svc := notify.NewTestService(http.DefaultTransport)
|
||||
svc.SetSlackWebhookURL(slackURL)
|
||||
|
||||
svc.SendNotification(
|
||||
context.Background(), "t", "m", "error",
|
||||
)
|
||||
|
||||
time.Sleep(100 * time.Millisecond)
|
||||
}
|
||||
|
||||
func TestSendNotificationMattermostError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusBadGateway)
|
||||
}),
|
||||
assertSendNotificationTolerates(
|
||||
t, http.StatusBadGateway, prioWarning,
|
||||
(*notify.Service).SetMattermostWebhookURL,
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
mmURL, _ := url.Parse(srv.URL)
|
||||
|
||||
svc := notify.NewTestService(http.DefaultTransport)
|
||||
svc.SetMattermostWebhookURL(mmURL)
|
||||
|
||||
svc.SendNotification(
|
||||
context.Background(), "t", "m", "warning",
|
||||
)
|
||||
|
||||
time.Sleep(100 * time.Millisecond)
|
||||
}
|
||||
|
||||
// ── SlackPayload JSON marshaling ──────────────────────────
|
||||
|
||||
@@ -32,11 +32,27 @@ func NewRequestForTest(
|
||||
// NewTestService creates a Service suitable for unit testing.
|
||||
// It discards log output and uses the given transport.
|
||||
func NewTestService(transport http.RoundTripper) *Service {
|
||||
return &Service{
|
||||
log: slog.New(slog.DiscardHandler),
|
||||
transport: transport,
|
||||
history: NewAlertHistory(),
|
||||
}
|
||||
return newService(slog.New(slog.DiscardHandler), transport)
|
||||
}
|
||||
|
||||
// NewTestServiceWithLogger creates a Service that writes to the
|
||||
// given handler, so tests can assert on emitted log records.
|
||||
func NewTestServiceWithLogger(
|
||||
transport http.RoundTripper,
|
||||
handler slog.Handler,
|
||||
) *Service {
|
||||
return newService(slog.New(handler), transport)
|
||||
}
|
||||
|
||||
// Drain exports drain for testing.
|
||||
func (svc *Service) Drain(ctx context.Context) {
|
||||
svc.drain(ctx)
|
||||
}
|
||||
|
||||
// OutstandingDeliveries reports how many delivery goroutines
|
||||
// are currently tracked as in flight.
|
||||
func (svc *Service) OutstandingDeliveries() int64 {
|
||||
return svc.outstanding.Load()
|
||||
}
|
||||
|
||||
// SetNtfyURL sets the ntfy URL on a Service for testing.
|
||||
|
||||
@@ -29,14 +29,14 @@ func TestAlertHistoryAddAndRecent(t *testing.T) {
|
||||
Timestamp: now.Add(-2 * time.Minute),
|
||||
Title: "first",
|
||||
Message: "msg1",
|
||||
Priority: "info",
|
||||
Priority: prioInfo,
|
||||
})
|
||||
|
||||
h.Add(notify.AlertEntry{
|
||||
Timestamp: now.Add(-1 * time.Minute),
|
||||
Title: "second",
|
||||
Message: "msg2",
|
||||
Priority: "warning",
|
||||
Priority: prioWarning,
|
||||
})
|
||||
|
||||
entries := h.Recent()
|
||||
|
||||
@@ -12,6 +12,8 @@ import (
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"sync"
|
||||
"sync/atomic"
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
@@ -115,19 +117,41 @@ type Service struct {
|
||||
history *AlertHistory
|
||||
retryConfig RetryConfig
|
||||
sleepFn func(time.Duration) <-chan time.Time
|
||||
|
||||
// Shutdown draining state. drainMu guards draining and
|
||||
// serialises it against the counter increment in
|
||||
// startDelivery; inFlight tracks the delivery goroutines
|
||||
// themselves and outstanding mirrors its count so a timed
|
||||
// out drain can report how many were abandoned.
|
||||
drainMu sync.Mutex
|
||||
draining bool
|
||||
inFlight sync.WaitGroup
|
||||
outstanding atomic.Int64
|
||||
abandon chan struct{}
|
||||
abandonOnce sync.Once
|
||||
}
|
||||
|
||||
// newService builds a Service with the fields every Service
|
||||
// needs regardless of how it was constructed.
|
||||
func newService(
|
||||
log *slog.Logger,
|
||||
transport http.RoundTripper,
|
||||
) *Service {
|
||||
return &Service{
|
||||
log: log,
|
||||
transport: transport,
|
||||
history: NewAlertHistory(),
|
||||
abandon: make(chan struct{}),
|
||||
}
|
||||
}
|
||||
|
||||
// New creates a new notify Service.
|
||||
func New(
|
||||
_ fx.Lifecycle,
|
||||
lifecycle fx.Lifecycle,
|
||||
params Params,
|
||||
) (*Service, error) {
|
||||
svc := &Service{
|
||||
log: params.Logger.Get(),
|
||||
transport: http.DefaultTransport,
|
||||
config: params.Config,
|
||||
history: NewAlertHistory(),
|
||||
}
|
||||
svc := newService(params.Logger.Get(), http.DefaultTransport)
|
||||
svc.config = params.Config
|
||||
|
||||
if params.Config.NtfyTopic != "" {
|
||||
u, err := ValidateWebhookURL(
|
||||
@@ -168,6 +192,14 @@ func New(
|
||||
svc.mattermostWebhookURL = u
|
||||
}
|
||||
|
||||
lifecycle.Append(fx.Hook{
|
||||
OnStop: func(ctx context.Context) error {
|
||||
svc.drain(ctx)
|
||||
|
||||
return nil
|
||||
},
|
||||
})
|
||||
|
||||
return svc, nil
|
||||
}
|
||||
|
||||
@@ -194,6 +226,32 @@ func (svc *Service) SendNotification(
|
||||
svc.dispatchMattermost(ctx, title, message, priority)
|
||||
}
|
||||
|
||||
// dispatch delivers a notification to one endpoint on a
|
||||
// tracked background goroutine.
|
||||
//
|
||||
// The delivery context is detached from ctx with
|
||||
// context.WithoutCancel so that a cancelled caller does not
|
||||
// kill a delivery already under way; the shutdown drain, not
|
||||
// the caller, decides how long deliveries may keep running.
|
||||
func (svc *Service) dispatch(
|
||||
ctx context.Context,
|
||||
endpoint string,
|
||||
send func(context.Context) error,
|
||||
) {
|
||||
notifyCtx := context.WithoutCancel(ctx)
|
||||
|
||||
svc.startDelivery(endpoint, func() {
|
||||
err := svc.deliverWithRetry(notifyCtx, endpoint, send)
|
||||
if err != nil {
|
||||
svc.log.Error(
|
||||
"failed to send notification after retries",
|
||||
"endpoint", endpoint,
|
||||
"error", err,
|
||||
)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
func (svc *Service) dispatchNtfy(
|
||||
ctx context.Context,
|
||||
title, message, priority string,
|
||||
@@ -202,26 +260,11 @@ func (svc *Service) dispatchNtfy(
|
||||
return
|
||||
}
|
||||
|
||||
go func() {
|
||||
notifyCtx := context.WithoutCancel(ctx)
|
||||
|
||||
err := svc.deliverWithRetry(
|
||||
notifyCtx, "ntfy",
|
||||
func(c context.Context) error {
|
||||
return svc.sendNtfy(
|
||||
c, svc.ntfyURL,
|
||||
title, message, priority,
|
||||
)
|
||||
},
|
||||
svc.dispatch(ctx, "ntfy", func(c context.Context) error {
|
||||
return svc.sendNtfy(
|
||||
c, svc.ntfyURL, title, message, priority,
|
||||
)
|
||||
if err != nil {
|
||||
svc.log.Error(
|
||||
"failed to send ntfy notification "+
|
||||
"after retries",
|
||||
"error", err,
|
||||
)
|
||||
}
|
||||
}()
|
||||
})
|
||||
}
|
||||
|
||||
func (svc *Service) dispatchSlack(
|
||||
@@ -232,26 +275,11 @@ func (svc *Service) dispatchSlack(
|
||||
return
|
||||
}
|
||||
|
||||
go func() {
|
||||
notifyCtx := context.WithoutCancel(ctx)
|
||||
|
||||
err := svc.deliverWithRetry(
|
||||
notifyCtx, "slack",
|
||||
func(c context.Context) error {
|
||||
return svc.sendSlack(
|
||||
c, svc.slackWebhookURL,
|
||||
title, message, priority,
|
||||
)
|
||||
},
|
||||
svc.dispatch(ctx, "slack", func(c context.Context) error {
|
||||
return svc.sendSlack(
|
||||
c, svc.slackWebhookURL, title, message, priority,
|
||||
)
|
||||
if err != nil {
|
||||
svc.log.Error(
|
||||
"failed to send slack notification "+
|
||||
"after retries",
|
||||
"error", err,
|
||||
)
|
||||
}
|
||||
}()
|
||||
})
|
||||
}
|
||||
|
||||
func (svc *Service) dispatchMattermost(
|
||||
@@ -262,26 +290,15 @@ func (svc *Service) dispatchMattermost(
|
||||
return
|
||||
}
|
||||
|
||||
go func() {
|
||||
notifyCtx := context.WithoutCancel(ctx)
|
||||
|
||||
err := svc.deliverWithRetry(
|
||||
notifyCtx, "mattermost",
|
||||
func(c context.Context) error {
|
||||
return svc.sendSlack(
|
||||
c, svc.mattermostWebhookURL,
|
||||
title, message, priority,
|
||||
)
|
||||
},
|
||||
)
|
||||
if err != nil {
|
||||
svc.log.Error(
|
||||
"failed to send mattermost notification "+
|
||||
"after retries",
|
||||
"error", err,
|
||||
svc.dispatch(
|
||||
ctx, "mattermost",
|
||||
func(c context.Context) error {
|
||||
return svc.sendSlack(
|
||||
c, svc.mattermostWebhookURL,
|
||||
title, message, priority,
|
||||
)
|
||||
}
|
||||
}()
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
func (svc *Service) sendNtfy(
|
||||
|
||||
@@ -2,6 +2,7 @@ package notify
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"math"
|
||||
"math/rand/v2"
|
||||
"time"
|
||||
@@ -69,7 +70,7 @@ func (rc RetryConfig) backoff(attempt int) time.Duration {
|
||||
lo := raw * (1 - jitterFraction)
|
||||
hi := raw * (1 + jitterFraction)
|
||||
|
||||
jittered := lo + rand.Float64()*(hi-lo) //nolint:gosec // jitter does not need crypto/rand
|
||||
jittered := lo + rand.Float64()*(hi-lo) //nolint:gosec // jitter needs no crypto/rand
|
||||
|
||||
return time.Duration(jittered)
|
||||
}
|
||||
@@ -121,6 +122,14 @@ func (svc *Service) deliverWithRetry(
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return ctx.Err()
|
||||
case <-svc.abandon:
|
||||
// Shutdown drained past its deadline; stop
|
||||
// sleeping rather than outlive the process.
|
||||
// A nil channel (Service built without a
|
||||
// constructor) simply never fires.
|
||||
return fmt.Errorf(
|
||||
"%w: %s", ErrDeliveryAbandoned, endpoint,
|
||||
)
|
||||
case <-svc.sleepFunc(delay):
|
||||
}
|
||||
}
|
||||
|
||||
119
internal/notify/shutdown.go
Normal file
119
internal/notify/shutdown.go
Normal file
@@ -0,0 +1,119 @@
|
||||
package notify
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
)
|
||||
|
||||
// ErrDeliveryAbandoned is returned by a retry loop that was
|
||||
// cut short because shutdown drained past its deadline.
|
||||
var ErrDeliveryAbandoned = errors.New(
|
||||
"notification delivery abandoned at shutdown",
|
||||
)
|
||||
|
||||
// startDelivery runs fn on its own goroutine while tracking it,
|
||||
// so that drain can wait for it during shutdown.
|
||||
//
|
||||
// The WaitGroup counter is incremented here, on the caller's
|
||||
// goroutine, before the worker exists: incrementing it inside
|
||||
// the worker would race with drain's Wait and could let
|
||||
// shutdown sail past a delivery that had not started yet.
|
||||
//
|
||||
// Once draining has begun the delivery is refused outright
|
||||
// rather than queued, so a steady stream of newly submitted
|
||||
// notifications cannot keep extending the drain.
|
||||
func (svc *Service) startDelivery(endpoint string, fn func()) {
|
||||
svc.drainMu.Lock()
|
||||
|
||||
if svc.draining {
|
||||
svc.drainMu.Unlock()
|
||||
|
||||
svc.log.Warn(
|
||||
"notification not dispatched: shutdown in progress",
|
||||
"endpoint", endpoint,
|
||||
)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
svc.outstanding.Add(1)
|
||||
|
||||
// WaitGroup.Go increments the counter synchronously, here,
|
||||
// and only then starts the goroutine.
|
||||
svc.inFlight.Go(func() {
|
||||
// Runs before the WaitGroup counter is decremented, so
|
||||
// a drain that times out reports an accurate count.
|
||||
defer svc.outstanding.Add(-1)
|
||||
|
||||
fn()
|
||||
})
|
||||
|
||||
svc.drainMu.Unlock()
|
||||
}
|
||||
|
||||
// drain waits for in-flight notification deliveries to finish.
|
||||
//
|
||||
// It first stops accepting new deliveries, then waits until
|
||||
// either every outstanding delivery has completed or ctx
|
||||
// expires — whichever comes first. ctx is the context fx
|
||||
// passes to the OnStop hook, so a permanently dead webhook
|
||||
// cannot hang shutdown indefinitely.
|
||||
//
|
||||
// When the deadline arrives with deliveries still outstanding,
|
||||
// the count is logged at warn level and the abandon channel is
|
||||
// closed, which releases any retry loop sleeping in backoff.
|
||||
// Deliveries already inside an HTTP round trip are bounded by
|
||||
// the existing httpClientTimeout instead.
|
||||
//
|
||||
// A ctx that is already expired on entry is not by itself cause
|
||||
// for alarm: if nothing is outstanding there is nothing to
|
||||
// abandon, and the drain says so at debug level rather than
|
||||
// warning about deliveries that do not exist.
|
||||
func (svc *Service) drain(ctx context.Context) {
|
||||
svc.drainMu.Lock()
|
||||
svc.draining = true
|
||||
svc.drainMu.Unlock()
|
||||
|
||||
done := make(chan struct{})
|
||||
|
||||
go func() {
|
||||
svc.inFlight.Wait()
|
||||
close(done)
|
||||
}()
|
||||
|
||||
select {
|
||||
case <-done:
|
||||
svc.log.Debug(
|
||||
"all in-flight notifications completed",
|
||||
)
|
||||
case <-ctx.Done():
|
||||
// outstanding is decremented before the WaitGroup
|
||||
// counter, and startDelivery can no longer add to it
|
||||
// now that draining is set, so a zero here means every
|
||||
// delivery really did finish. ctx expiring in that
|
||||
// state (an OnStop context that was already cancelled
|
||||
// on entry is the usual way) abandons nothing, so it
|
||||
// must not close abandon or warn about it.
|
||||
abandoned := svc.outstanding.Load()
|
||||
if abandoned == 0 {
|
||||
svc.log.Debug(
|
||||
"all in-flight notifications completed",
|
||||
)
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
svc.abandonOnce.Do(func() {
|
||||
if svc.abandon != nil {
|
||||
close(svc.abandon)
|
||||
}
|
||||
})
|
||||
|
||||
svc.log.Warn(
|
||||
"shutdown deadline reached with notifications "+
|
||||
"still in flight; abandoning them",
|
||||
"abandoned", abandoned,
|
||||
"error", ctx.Err(),
|
||||
)
|
||||
}
|
||||
}
|
||||
531
internal/notify/shutdown_test.go
Normal file
531
internal/notify/shutdown_test.go
Normal file
@@ -0,0 +1,531 @@
|
||||
package notify_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"strings"
|
||||
"sync"
|
||||
"sync/atomic"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
|
||||
"sneak.berlin/go/dnswatcher/internal/config"
|
||||
"sneak.berlin/go/dnswatcher/internal/globals"
|
||||
"sneak.berlin/go/dnswatcher/internal/logger"
|
||||
"sneak.berlin/go/dnswatcher/internal/notify"
|
||||
)
|
||||
|
||||
// Timings used by the drain tests. They stay in the same
|
||||
// 10-100ms band as the retry tests so the suite never waits on
|
||||
// a real backoff delay.
|
||||
const (
|
||||
// inFlightHold is how long a delivery is kept mid-request
|
||||
// before the handler is released.
|
||||
inFlightHold = 30 * time.Millisecond
|
||||
|
||||
// drainDeadline bounds a drain that is expected to time
|
||||
// out.
|
||||
drainDeadline = 50 * time.Millisecond
|
||||
|
||||
// drainSlack is the upper bound on how long a bounded
|
||||
// drain may take; generous enough for a loaded CI box,
|
||||
// still far below the 20s test ceiling.
|
||||
drainSlack = 2 * time.Second
|
||||
|
||||
// settleDelay is how long to wait before asserting that
|
||||
// something did *not* happen.
|
||||
settleDelay = 50 * time.Millisecond
|
||||
|
||||
// idleDrainBound is the upper bound on a drain that has
|
||||
// nothing in flight. It is deliberately far above the cost
|
||||
// of the goroutine hop through inFlight.Wait() — which
|
||||
// reached 57ms on a loaded box under -race with the package's
|
||||
// parallel tests — and far below drainSlack, the deadline
|
||||
// such a drain is given. A drain that blocked until its
|
||||
// deadline instead of returning on the WaitGroup therefore
|
||||
// still fails this bound, but scheduling delay alone cannot.
|
||||
idleDrainBound = 500 * time.Millisecond
|
||||
)
|
||||
|
||||
// syncBuffer is an io.Writer safe for concurrent use, so log
|
||||
// output written from delivery goroutines can be inspected.
|
||||
type syncBuffer struct {
|
||||
mu sync.Mutex
|
||||
buf bytes.Buffer
|
||||
}
|
||||
|
||||
func (sb *syncBuffer) Write(p []byte) (int, error) {
|
||||
sb.mu.Lock()
|
||||
defer sb.mu.Unlock()
|
||||
|
||||
return sb.buf.Write(p) //nolint:wrapcheck // test helper
|
||||
}
|
||||
|
||||
func (sb *syncBuffer) String() string {
|
||||
sb.mu.Lock()
|
||||
defer sb.mu.Unlock()
|
||||
|
||||
return sb.buf.String()
|
||||
}
|
||||
|
||||
// newLoggingService returns a Service writing JSON logs into
|
||||
// the returned buffer.
|
||||
func newLoggingService(
|
||||
transport http.RoundTripper,
|
||||
) (*notify.Service, *syncBuffer) {
|
||||
logs := &syncBuffer{}
|
||||
handler := slog.NewJSONHandler(logs, nil)
|
||||
|
||||
return notify.NewTestServiceWithLogger(transport, handler),
|
||||
logs
|
||||
}
|
||||
|
||||
// blockingNtfyServer returns a server whose handler signals on
|
||||
// entered, waits for release, and then responds 200.
|
||||
func blockingNtfyServer(
|
||||
entered chan<- struct{},
|
||||
release <-chan struct{},
|
||||
served *atomic.Bool,
|
||||
) *httptest.Server {
|
||||
var once sync.Once
|
||||
|
||||
return httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
once.Do(func() { close(entered) })
|
||||
<-release
|
||||
|
||||
served.Store(true)
|
||||
|
||||
w.WriteHeader(http.StatusOK)
|
||||
}),
|
||||
)
|
||||
}
|
||||
|
||||
// TestDrainWaitsForInFlightDelivery verifies that a delivery
|
||||
// already under way when shutdown starts is allowed to finish.
|
||||
func TestDrainWaitsForInFlightDelivery(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var served atomic.Bool
|
||||
|
||||
entered := make(chan struct{})
|
||||
release := make(chan struct{})
|
||||
|
||||
srv := blockingNtfyServer(entered, release, &served)
|
||||
defer srv.Close()
|
||||
|
||||
topicURL, _ := url.Parse(srv.URL)
|
||||
|
||||
svc := notify.NewTestService(http.DefaultTransport)
|
||||
svc.SetNtfyURL(topicURL)
|
||||
|
||||
svc.SendNotification(
|
||||
context.Background(), "t", "m", prioInfo,
|
||||
)
|
||||
|
||||
// Make sure the delivery really is mid-request before the
|
||||
// drain begins.
|
||||
select {
|
||||
case <-entered:
|
||||
case <-time.After(drainSlack):
|
||||
t.Fatal("delivery never reached the endpoint")
|
||||
}
|
||||
|
||||
// As in TestDrainBoundedByContextDeadline: start is captured
|
||||
// before the clock it is compared against, here the timer
|
||||
// holding the delivery open, so elapsed covers the whole hold
|
||||
// and the lower bound cannot come out short from scheduling
|
||||
// delay alone.
|
||||
start := time.Now()
|
||||
|
||||
timer := time.AfterFunc(inFlightHold, func() {
|
||||
close(release)
|
||||
})
|
||||
defer timer.Stop()
|
||||
|
||||
ctx, cancel := context.WithTimeout(
|
||||
context.Background(), drainSlack,
|
||||
)
|
||||
defer cancel()
|
||||
|
||||
svc.Drain(ctx)
|
||||
|
||||
elapsed := time.Since(start)
|
||||
|
||||
if !served.Load() {
|
||||
t.Error(
|
||||
"drain returned before the in-flight delivery " +
|
||||
"completed",
|
||||
)
|
||||
}
|
||||
|
||||
if elapsed < inFlightHold {
|
||||
t.Errorf(
|
||||
"drain took %v, want at least %v",
|
||||
elapsed, inFlightHold,
|
||||
)
|
||||
}
|
||||
|
||||
if got := svc.OutstandingDeliveries(); got != 0 {
|
||||
t.Errorf("outstanding deliveries = %d, want 0", got)
|
||||
}
|
||||
}
|
||||
|
||||
// neverFires returns a channel that never delivers, standing in
|
||||
// for a long backoff sleep without actually sleeping.
|
||||
func neverFires(_ time.Duration) <-chan time.Time {
|
||||
return make(chan time.Time)
|
||||
}
|
||||
|
||||
// TestDrainBoundedByContextDeadline verifies that a delivery
|
||||
// stuck retrying against a dead endpoint does not hold shutdown
|
||||
// past the OnStop context deadline, and that the abandoned
|
||||
// deliveries are logged at warn level rather than dropped
|
||||
// silently.
|
||||
func TestDrainBoundedByContextDeadline(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var requests atomic.Int64
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
requests.Add(1)
|
||||
|
||||
w.WriteHeader(http.StatusInternalServerError)
|
||||
}),
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
topicURL, _ := url.Parse(srv.URL)
|
||||
|
||||
svc, logs := newLoggingService(http.DefaultTransport)
|
||||
svc.SetNtfyURL(topicURL)
|
||||
// Never let the backoff sleep complete: the delivery is
|
||||
// parked in its retry wait until shutdown releases it.
|
||||
svc.SetSleepFunc(neverFires)
|
||||
svc.SetRetryConfig(notify.RetryConfig{
|
||||
MaxRetries: 5,
|
||||
BaseDelay: time.Hour,
|
||||
MaxDelay: time.Hour,
|
||||
})
|
||||
|
||||
svc.SendNotification(
|
||||
context.Background(), "t", "m", prioError,
|
||||
)
|
||||
|
||||
waitForCondition(t, func() bool {
|
||||
return requests.Load() >= 1 &&
|
||||
svc.OutstandingDeliveries() == 1
|
||||
})
|
||||
|
||||
// start must be captured *before* the deadline clock starts,
|
||||
// so that the measured interval is a superset of the deadline
|
||||
// interval. Capturing it after context.WithTimeout would
|
||||
// make elapsed structurally smaller than drainDeadline and
|
||||
// the lower bound below unfalsifiable-by-luck: it would fail
|
||||
// whenever the two statements were separated by any
|
||||
// scheduling delay, and pass otherwise, regardless of what
|
||||
// the drain did.
|
||||
start := time.Now()
|
||||
|
||||
ctx, cancel := context.WithTimeout(
|
||||
context.Background(), drainDeadline,
|
||||
)
|
||||
defer cancel()
|
||||
|
||||
// The upper bound is enforced by a watchdog rather than by
|
||||
// measuring after the fact: a drain that is not bounded at
|
||||
// all never returns here (the delivery is parked in a backoff
|
||||
// that never fires), so an unbounded drain must fail this
|
||||
// test promptly instead of hanging the package until the test
|
||||
// binary's 30s timeout.
|
||||
returned := make(chan struct{})
|
||||
|
||||
go func() {
|
||||
defer close(returned)
|
||||
|
||||
svc.Drain(ctx)
|
||||
}()
|
||||
|
||||
select {
|
||||
case <-returned:
|
||||
case <-time.After(drainSlack):
|
||||
t.Fatalf(
|
||||
"drain did not return within %v; its %v deadline "+
|
||||
"did not bound it",
|
||||
drainSlack, drainDeadline,
|
||||
)
|
||||
}
|
||||
|
||||
// The lower bound is the real assertion: the drain must have
|
||||
// waited for its whole deadline rather than giving up on the
|
||||
// outstanding delivery early. With start captured above, an
|
||||
// early return is the only thing that can make it fail.
|
||||
if elapsed := time.Since(start); elapsed < drainDeadline {
|
||||
t.Errorf(
|
||||
"drain returned after %v, before its %v deadline",
|
||||
elapsed, drainDeadline,
|
||||
)
|
||||
}
|
||||
|
||||
assertAbandonLogged(t, logs.String())
|
||||
|
||||
// The abandoned delivery must stop retrying rather than
|
||||
// outlive the drain.
|
||||
waitForCondition(t, func() bool {
|
||||
return svc.OutstandingDeliveries() == 0
|
||||
})
|
||||
}
|
||||
|
||||
// assertAbandonLogged checks that the drain logged the
|
||||
// abandoned deliveries at warn level with a count.
|
||||
func assertAbandonLogged(t *testing.T, output string) {
|
||||
t.Helper()
|
||||
|
||||
if !strings.Contains(output, `"level":"WARN"`) {
|
||||
t.Errorf(
|
||||
"abandoned deliveries not logged at warn level; "+
|
||||
"log output: %s",
|
||||
output,
|
||||
)
|
||||
}
|
||||
|
||||
if !strings.Contains(output, `"abandoned":1`) {
|
||||
t.Errorf(
|
||||
"abandoned delivery count not logged; "+
|
||||
"log output: %s",
|
||||
output,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// TestDrainRefusesNewDeliveries verifies that notifications
|
||||
// submitted after the drain has begun are refused and logged,
|
||||
// so a stream of new work cannot extend shutdown indefinitely.
|
||||
func TestDrainRefusesNewDeliveries(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var requests atomic.Int64
|
||||
|
||||
srv := httptest.NewServer(
|
||||
http.HandlerFunc(
|
||||
func(w http.ResponseWriter, _ *http.Request) {
|
||||
requests.Add(1)
|
||||
|
||||
w.WriteHeader(http.StatusOK)
|
||||
}),
|
||||
)
|
||||
defer srv.Close()
|
||||
|
||||
target, _ := url.Parse(srv.URL)
|
||||
|
||||
svc, logs := newLoggingService(http.DefaultTransport)
|
||||
svc.SetNtfyURL(target)
|
||||
svc.SetSlackWebhookURL(target)
|
||||
svc.SetMattermostWebhookURL(target)
|
||||
|
||||
ctx, cancel := context.WithTimeout(
|
||||
context.Background(), drainSlack,
|
||||
)
|
||||
defer cancel()
|
||||
|
||||
// Nothing is in flight, so this returns immediately and
|
||||
// leaves the service refusing further deliveries.
|
||||
svc.Drain(ctx)
|
||||
|
||||
for range 3 {
|
||||
svc.SendNotification(
|
||||
context.Background(), "t", "m", prioInfo,
|
||||
)
|
||||
}
|
||||
|
||||
time.Sleep(settleDelay)
|
||||
|
||||
if got := requests.Load(); got != 0 {
|
||||
t.Errorf(
|
||||
"%d requests reached the endpoint after drain, "+
|
||||
"want 0",
|
||||
got,
|
||||
)
|
||||
}
|
||||
|
||||
if got := svc.OutstandingDeliveries(); got != 0 {
|
||||
t.Errorf("outstanding deliveries = %d, want 0", got)
|
||||
}
|
||||
|
||||
output := logs.String()
|
||||
if !strings.Contains(output, "shutdown in progress") {
|
||||
t.Errorf(
|
||||
"refused deliveries not logged; log output: %s",
|
||||
output,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// recordingLifecycle is a minimal fx.Lifecycle that records the
|
||||
// hooks appended to it, so the wiring done by notify.New can be
|
||||
// inspected without standing up a whole fx application.
|
||||
type recordingLifecycle struct {
|
||||
hooks []fx.Hook
|
||||
}
|
||||
|
||||
func (l *recordingLifecycle) Append(hook fx.Hook) {
|
||||
l.hooks = append(l.hooks, hook)
|
||||
}
|
||||
|
||||
// newNotifyService builds a Service through the real
|
||||
// constructor, wired to the given lifecycle.
|
||||
func newNotifyService(
|
||||
t *testing.T,
|
||||
lifecycle fx.Lifecycle,
|
||||
ntfyTopic string,
|
||||
) *notify.Service {
|
||||
t.Helper()
|
||||
|
||||
g, err := globals.New(nil)
|
||||
if err != nil {
|
||||
t.Fatalf("globals.New: %v", err)
|
||||
}
|
||||
|
||||
log, err := logger.New(nil, logger.Params{Globals: g})
|
||||
if err != nil {
|
||||
t.Fatalf("logger.New: %v", err)
|
||||
}
|
||||
|
||||
svc, err := notify.New(lifecycle, notify.Params{
|
||||
Logger: log,
|
||||
Config: &config.Config{NtfyTopic: ntfyTopic},
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("notify.New: %v", err)
|
||||
}
|
||||
|
||||
return svc
|
||||
}
|
||||
|
||||
// TestNewRegistersDrainingStopHook verifies that notify.New
|
||||
// wires an OnStop hook into the fx lifecycle and that the hook
|
||||
// waits for in-flight deliveries.
|
||||
func TestNewRegistersDrainingStopHook(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
var served atomic.Bool
|
||||
|
||||
entered := make(chan struct{})
|
||||
release := make(chan struct{})
|
||||
|
||||
srv := blockingNtfyServer(entered, release, &served)
|
||||
defer srv.Close()
|
||||
|
||||
lifecycle := &recordingLifecycle{}
|
||||
svc := newNotifyService(t, lifecycle, srv.URL)
|
||||
|
||||
if len(lifecycle.hooks) != 1 {
|
||||
t.Fatalf(
|
||||
"appended %d lifecycle hooks, want 1",
|
||||
len(lifecycle.hooks),
|
||||
)
|
||||
}
|
||||
|
||||
stop := lifecycle.hooks[0].OnStop
|
||||
if stop == nil {
|
||||
t.Fatal("lifecycle hook has no OnStop function")
|
||||
}
|
||||
|
||||
svc.SendNotification(
|
||||
context.Background(), "t", "m", prioInfo,
|
||||
)
|
||||
|
||||
select {
|
||||
case <-entered:
|
||||
case <-time.After(drainSlack):
|
||||
t.Fatal("delivery never reached the endpoint")
|
||||
}
|
||||
|
||||
timer := time.AfterFunc(inFlightHold, func() {
|
||||
close(release)
|
||||
})
|
||||
defer timer.Stop()
|
||||
|
||||
ctx, cancel := context.WithTimeout(
|
||||
context.Background(), drainSlack,
|
||||
)
|
||||
defer cancel()
|
||||
|
||||
err := stop(ctx)
|
||||
if err != nil {
|
||||
t.Fatalf("OnStop returned error: %v", err)
|
||||
}
|
||||
|
||||
if !served.Load() {
|
||||
t.Error(
|
||||
"OnStop returned before the in-flight delivery " +
|
||||
"completed",
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// TestDrainWithoutDeliveriesReturnsImmediately verifies the
|
||||
// common case: nothing in flight, shutdown is not delayed.
|
||||
func TestDrainWithoutDeliveriesReturnsImmediately(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
svc := notify.NewTestService(http.DefaultTransport)
|
||||
|
||||
// Captured before the deadline clock, as elsewhere in this
|
||||
// file; for an upper bound that is the conservative
|
||||
// direction, since the measured interval can then only be
|
||||
// longer than the drain itself.
|
||||
start := time.Now()
|
||||
|
||||
ctx, cancel := context.WithTimeout(
|
||||
context.Background(), drainSlack,
|
||||
)
|
||||
defer cancel()
|
||||
|
||||
svc.Drain(ctx)
|
||||
|
||||
if elapsed := time.Since(start); elapsed > idleDrainBound {
|
||||
t.Errorf(
|
||||
"drain of an idle service took %v, want well "+
|
||||
"under its %v deadline",
|
||||
elapsed, drainSlack,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// TestDrainWithCancelledContextDoesNotWarn verifies that an
|
||||
// OnStop context that is already dead on entry does not produce
|
||||
// an "abandoning them" warning when there was nothing in flight
|
||||
// to abandon. The expired context wins the select immediately,
|
||||
// so only the outstanding count can tell the difference between
|
||||
// a genuine timeout and a shutdown that had simply already run
|
||||
// out of time with no work left.
|
||||
func TestDrainWithCancelledContextDoesNotWarn(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
svc, logs := newLoggingService(http.DefaultTransport)
|
||||
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
cancel()
|
||||
|
||||
svc.Drain(ctx)
|
||||
|
||||
if output := logs.String(); strings.Contains(
|
||||
output, `"level":"WARN"`,
|
||||
) {
|
||||
t.Errorf(
|
||||
"drain with nothing in flight warned about "+
|
||||
"abandoned deliveries; log output: %s",
|
||||
output,
|
||||
)
|
||||
}
|
||||
}
|
||||
@@ -13,6 +13,16 @@ import (
|
||||
|
||||
const testHostname = "www.example.com"
|
||||
|
||||
// Shared fixture values used across tests.
|
||||
const (
|
||||
testNS1 = "ns1.example.com."
|
||||
testNS2 = "ns2.example.com."
|
||||
testAltNS1 = "ns1.test.com."
|
||||
testIPv4 = "93.184.216.34"
|
||||
testIP = "1.2.3.4"
|
||||
statusError = "error"
|
||||
)
|
||||
|
||||
// populateState fills a State with representative test data across all categories.
|
||||
func populateState(t *testing.T, s *state.State) {
|
||||
t.Helper()
|
||||
@@ -20,7 +30,7 @@ func populateState(t *testing.T, s *state.State) {
|
||||
now := time.Now().UTC().Truncate(time.Second)
|
||||
|
||||
s.SetDomainState("example.com", &state.DomainState{
|
||||
Nameservers: []string{"ns1.example.com.", "ns2.example.com."},
|
||||
Nameservers: []string{testNS1, testNS2},
|
||||
LastChecked: now,
|
||||
})
|
||||
|
||||
@@ -31,17 +41,17 @@ func populateState(t *testing.T, s *state.State) {
|
||||
|
||||
s.SetHostnameState(testHostname, &state.HostnameState{
|
||||
RecordsByNameserver: map[string]*state.NameserverRecordState{
|
||||
"ns1.example.com.": {
|
||||
testNS1: {
|
||||
Records: map[string][]string{
|
||||
"A": {"93.184.216.34"},
|
||||
"A": {testIPv4},
|
||||
"AAAA": {"2606:2800:220:1:248:1893:25c8:1946"},
|
||||
},
|
||||
Status: "ok",
|
||||
LastChecked: now,
|
||||
},
|
||||
"ns2.example.com.": {
|
||||
testNS2: {
|
||||
Records: map[string][]string{
|
||||
"A": {"93.184.216.34"},
|
||||
"A": {testIPv4},
|
||||
},
|
||||
Status: "ok",
|
||||
LastChecked: now,
|
||||
@@ -152,13 +162,13 @@ func TestSaveLoadRoundTrip_Hostnames(t *testing.T) {
|
||||
func verifyNS1Records(t *testing.T, hn *state.HostnameState) {
|
||||
t.Helper()
|
||||
|
||||
ns1, ok := hn.RecordsByNameserver["ns1.example.com."]
|
||||
ns1, ok := hn.RecordsByNameserver[testNS1]
|
||||
if !ok {
|
||||
t.Fatal("missing nameserver ns1.example.com.")
|
||||
}
|
||||
|
||||
aRecords := ns1.Records["A"]
|
||||
if len(aRecords) != 1 || aRecords[0] != "93.184.216.34" {
|
||||
if len(aRecords) != 1 || aRecords[0] != testIPv4 {
|
||||
t.Errorf("ns1 A records: got %v", aRecords)
|
||||
}
|
||||
|
||||
@@ -213,7 +223,8 @@ func TestSaveLoadRoundTrip_Ports(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// TestSaveLoadRoundTrip_Certificates verifies certificate data survives a save/load cycle.
|
||||
// TestSaveLoadRoundTrip_Certificates verifies certificate data
|
||||
// survives a save/load cycle.
|
||||
func TestSaveLoadRoundTrip_Certificates(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -653,7 +664,7 @@ func TestDomainState_GetSet(t *testing.T) {
|
||||
|
||||
now := time.Now().UTC().Truncate(time.Second)
|
||||
ds := &state.DomainState{
|
||||
Nameservers: []string{"ns1.test.com."},
|
||||
Nameservers: []string{testAltNS1},
|
||||
LastChecked: now,
|
||||
}
|
||||
|
||||
@@ -664,7 +675,7 @@ func TestDomainState_GetSet(t *testing.T) {
|
||||
t.Fatal("expected true for existing domain")
|
||||
}
|
||||
|
||||
if len(got.Nameservers) != 1 || got.Nameservers[0] != "ns1.test.com." {
|
||||
if len(got.Nameservers) != 1 || got.Nameservers[0] != testAltNS1 {
|
||||
t.Errorf("nameservers: got %v", got.Nameservers)
|
||||
}
|
||||
|
||||
@@ -674,7 +685,7 @@ func TestDomainState_GetSet(t *testing.T) {
|
||||
|
||||
// Overwrite.
|
||||
ds2 := &state.DomainState{
|
||||
Nameservers: []string{"ns1.test.com.", "ns2.test.com."},
|
||||
Nameservers: []string{testAltNS1, "ns2.test.com."},
|
||||
LastChecked: now.Add(time.Hour),
|
||||
}
|
||||
|
||||
@@ -704,8 +715,8 @@ func TestHostnameState_GetSet(t *testing.T) {
|
||||
now := time.Now().UTC().Truncate(time.Second)
|
||||
hs := &state.HostnameState{
|
||||
RecordsByNameserver: map[string]*state.NameserverRecordState{
|
||||
"ns1.example.com.": {
|
||||
Records: map[string][]string{"A": {"1.2.3.4"}},
|
||||
testNS1: {
|
||||
Records: map[string][]string{"A": {testIP}},
|
||||
Status: "ok",
|
||||
LastChecked: now,
|
||||
},
|
||||
@@ -720,7 +731,7 @@ func TestHostnameState_GetSet(t *testing.T) {
|
||||
t.Fatal("expected true for existing hostname")
|
||||
}
|
||||
|
||||
nsState, ok := got.RecordsByNameserver["ns1.example.com."]
|
||||
nsState, ok := got.RecordsByNameserver[testNS1]
|
||||
if !ok {
|
||||
t.Fatal("missing nameserver entry")
|
||||
}
|
||||
@@ -730,7 +741,7 @@ func TestHostnameState_GetSet(t *testing.T) {
|
||||
}
|
||||
|
||||
aRecords := nsState.Records["A"]
|
||||
if len(aRecords) != 1 || aRecords[0] != "1.2.3.4" {
|
||||
if len(aRecords) != 1 || aRecords[0] != testIP {
|
||||
t.Errorf("A records: got %v", aRecords)
|
||||
}
|
||||
}
|
||||
@@ -869,7 +880,7 @@ func TestCertificateState_ErrorField(t *testing.T) {
|
||||
|
||||
now := time.Now().UTC().Truncate(time.Second)
|
||||
cs := &state.CertificateState{
|
||||
Status: "error",
|
||||
Status: statusError,
|
||||
Error: "connection refused",
|
||||
LastChecked: now,
|
||||
}
|
||||
@@ -893,8 +904,8 @@ func TestCertificateState_ErrorField(t *testing.T) {
|
||||
t.Fatal("missing certificate after load")
|
||||
}
|
||||
|
||||
if got.Status != "error" {
|
||||
t.Errorf("status: got %q, want %q", got.Status, "error")
|
||||
if got.Status != statusError {
|
||||
t.Errorf("status: got %q, want %q", got.Status, statusError)
|
||||
}
|
||||
|
||||
if got.Error != "connection refused" {
|
||||
@@ -912,9 +923,9 @@ func TestHostnameState_ErrorField(t *testing.T) {
|
||||
now := time.Now().UTC().Truncate(time.Second)
|
||||
hs := &state.HostnameState{
|
||||
RecordsByNameserver: map[string]*state.NameserverRecordState{
|
||||
"ns1.example.com.": {
|
||||
testNS1: {
|
||||
Records: nil,
|
||||
Status: "error",
|
||||
Status: statusError,
|
||||
Error: "SERVFAIL",
|
||||
LastChecked: now,
|
||||
},
|
||||
@@ -941,9 +952,9 @@ func TestHostnameState_ErrorField(t *testing.T) {
|
||||
t.Fatal("missing hostname after load")
|
||||
}
|
||||
|
||||
nsState := got.RecordsByNameserver["ns1.example.com."]
|
||||
if nsState.Status != "error" {
|
||||
t.Errorf("status: got %q, want %q", nsState.Status, "error")
|
||||
nsState := got.RecordsByNameserver[testNS1]
|
||||
if nsState.Status != statusError {
|
||||
t.Errorf("status: got %q, want %q", nsState.Status, statusError)
|
||||
}
|
||||
|
||||
if nsState.Error != "SERVFAIL" {
|
||||
@@ -1062,7 +1073,8 @@ func TestConcurrentGetSet(t *testing.T) {
|
||||
wg.Wait()
|
||||
}
|
||||
|
||||
// runConcurrentOps performs a series of get/set/delete operations for concurrency testing.
|
||||
// runConcurrentOps performs a series of get/set/delete
|
||||
// operations for concurrency testing.
|
||||
func runConcurrentOps(s *state.State, key string, now time.Time) {
|
||||
const iterations = 50
|
||||
|
||||
@@ -1085,7 +1097,7 @@ func runConcurrentOps(s *state.State, key string, now time.Time) {
|
||||
s.SetHostnameState(key+".example.com", &state.HostnameState{
|
||||
RecordsByNameserver: map[string]*state.NameserverRecordState{
|
||||
"ns1.test.": {
|
||||
Records: map[string][]string{"A": {"1.2.3.4"}},
|
||||
Records: map[string][]string{"A": {testIP}},
|
||||
Status: "ok",
|
||||
LastChecked: now,
|
||||
},
|
||||
|
||||
@@ -26,6 +26,12 @@ const tlsPort = 443
|
||||
// hoursPerDay converts days to hours for duration calculations.
|
||||
const hoursPerDay = 24
|
||||
|
||||
// Status values recorded for nameserver and certificate checks.
|
||||
const (
|
||||
statusOK = "ok"
|
||||
statusError = "error"
|
||||
)
|
||||
|
||||
// Params contains dependencies for Watcher.
|
||||
type Params struct {
|
||||
fx.In
|
||||
@@ -344,7 +350,7 @@ func buildHostnameState(
|
||||
for ns, recs := range records {
|
||||
hs.RecordsByNameserver[ns] = &state.NameserverRecordState{
|
||||
Records: recs,
|
||||
Status: "ok",
|
||||
Status: statusOK,
|
||||
LastChecked: now,
|
||||
}
|
||||
}
|
||||
@@ -402,7 +408,7 @@ func (w *Watcher) detectNSDisappearances(
|
||||
current map[string]map[string][]string,
|
||||
) {
|
||||
for ns, prevNS := range prev.RecordsByNameserver {
|
||||
if _, ok := current[ns]; ok || prevNS.Status != "ok" {
|
||||
if _, ok := current[ns]; ok || prevNS.Status != statusOK {
|
||||
continue
|
||||
}
|
||||
|
||||
@@ -421,7 +427,7 @@ func (w *Watcher) detectNSDisappearances(
|
||||
|
||||
for ns := range current {
|
||||
prevNS, ok := prev.RecordsByNameserver[ns]
|
||||
if !ok || prevNS.Status != "error" {
|
||||
if !ok || prevNS.Status != statusError {
|
||||
continue
|
||||
}
|
||||
|
||||
@@ -705,7 +711,7 @@ func (w *Watcher) handleTLSError(
|
||||
now time.Time,
|
||||
err error,
|
||||
) {
|
||||
if hasPrev && !w.firstRun && prev.Status == "ok" {
|
||||
if hasPrev && !w.firstRun && prev.Status == statusOK {
|
||||
msg := fmt.Sprintf(
|
||||
"Host: %s\nIP: %s\nError: %s",
|
||||
hostname, ip, err,
|
||||
@@ -721,7 +727,7 @@ func (w *Watcher) handleTLSError(
|
||||
|
||||
w.state.SetCertificateState(
|
||||
certKey, &state.CertificateState{
|
||||
Status: "error",
|
||||
Status: statusError,
|
||||
Error: err.Error(),
|
||||
LastChecked: now,
|
||||
},
|
||||
@@ -748,7 +754,7 @@ func (w *Watcher) handleTLSSuccess(
|
||||
Issuer: cert.Issuer,
|
||||
NotAfter: cert.NotAfter,
|
||||
SubjectAlternativeNames: cert.SubjectAlternativeNames,
|
||||
Status: "ok",
|
||||
Status: statusOK,
|
||||
LastChecked: now,
|
||||
},
|
||||
)
|
||||
@@ -760,7 +766,7 @@ func (w *Watcher) detectTLSChanges(
|
||||
prev *state.CertificateState,
|
||||
cert *tlscheck.CertificateInfo,
|
||||
) {
|
||||
if prev.Status == "error" {
|
||||
if prev.Status == statusError {
|
||||
msg := fmt.Sprintf(
|
||||
"Host: %s\nIP: %s\nTLS recovered",
|
||||
hostname, ip,
|
||||
|
||||
@@ -18,6 +18,17 @@ import (
|
||||
// errNotFound is returned when mock data is missing.
|
||||
var errNotFound = errors.New("not found")
|
||||
|
||||
// Fixture values shared across tests.
|
||||
const (
|
||||
testDomain = "example.com"
|
||||
testHost = "www.example.com"
|
||||
testNS1 = "ns1.example.com."
|
||||
testNS2 = "ns2.example.com."
|
||||
testIPv4 = "93.184.216.34"
|
||||
testIP = "1.2.3.4"
|
||||
testIssuer = "DigiCert"
|
||||
)
|
||||
|
||||
// --- Mock implementations ---
|
||||
|
||||
type mockResolver struct {
|
||||
@@ -256,8 +267,8 @@ func TestFirstRunBaseline(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{"example.com"}
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Domains = []string{testDomain}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
setupBaselineMocks(deps)
|
||||
@@ -269,37 +280,37 @@ func TestFirstRunBaseline(t *testing.T) {
|
||||
}
|
||||
|
||||
func setupBaselineMocks(deps *testDeps) {
|
||||
deps.resolver.nsRecords["example.com"] = []string{
|
||||
"ns1.example.com.",
|
||||
"ns2.example.com.",
|
||||
deps.resolver.nsRecords[testDomain] = []string{
|
||||
testNS1,
|
||||
testNS2,
|
||||
}
|
||||
deps.resolver.allRecords["example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"93.184.216.34"}},
|
||||
"ns2.example.com.": {"A": {"93.184.216.34"}},
|
||||
deps.resolver.allRecords[testDomain] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIPv4}},
|
||||
testNS2: {"A": {testIPv4}},
|
||||
}
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"93.184.216.34"}},
|
||||
"ns2.example.com.": {"A": {"93.184.216.34"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIPv4}},
|
||||
testNS2: {"A": {testIPv4}},
|
||||
}
|
||||
deps.resolver.ipAddresses["www.example.com"] = []string{
|
||||
"93.184.216.34",
|
||||
deps.resolver.ipAddresses[testHost] = []string{
|
||||
testIPv4,
|
||||
}
|
||||
deps.portChecker.results["93.184.216.34:80"] = true
|
||||
deps.portChecker.results["93.184.216.34:443"] = true
|
||||
deps.tlsChecker.certs["93.184.216.34:www.example.com"] = &tlscheck.CertificateInfo{
|
||||
CommonName: "www.example.com",
|
||||
Issuer: "DigiCert",
|
||||
CommonName: testHost,
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(90 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{
|
||||
"www.example.com",
|
||||
testHost,
|
||||
},
|
||||
}
|
||||
deps.tlsChecker.certs["93.184.216.34:example.com"] = &tlscheck.CertificateInfo{
|
||||
CommonName: "example.com",
|
||||
Issuer: "DigiCert",
|
||||
CommonName: testDomain,
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(90 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{
|
||||
"example.com",
|
||||
testDomain,
|
||||
},
|
||||
}
|
||||
}
|
||||
@@ -348,24 +359,24 @@ func TestDomainPortAndTLSChecks(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{"example.com"}
|
||||
cfg.Domains = []string{testDomain}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.nsRecords["example.com"] = []string{
|
||||
"ns1.example.com.",
|
||||
deps.resolver.nsRecords[testDomain] = []string{
|
||||
testNS1,
|
||||
}
|
||||
deps.resolver.allRecords["example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"93.184.216.34"}},
|
||||
deps.resolver.allRecords[testDomain] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIPv4}},
|
||||
}
|
||||
deps.portChecker.results["93.184.216.34:80"] = true
|
||||
deps.portChecker.results["93.184.216.34:443"] = true
|
||||
deps.tlsChecker.certs["93.184.216.34:example.com"] = &tlscheck.CertificateInfo{
|
||||
CommonName: "example.com",
|
||||
Issuer: "DigiCert",
|
||||
CommonName: testDomain,
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(90 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{
|
||||
"example.com",
|
||||
testDomain,
|
||||
},
|
||||
}
|
||||
|
||||
@@ -406,17 +417,17 @@ func TestNSChangeDetection(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{"example.com"}
|
||||
cfg.Domains = []string{testDomain}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.nsRecords["example.com"] = []string{
|
||||
"ns1.example.com.",
|
||||
"ns2.example.com.",
|
||||
deps.resolver.nsRecords[testDomain] = []string{
|
||||
testNS1,
|
||||
testNS2,
|
||||
}
|
||||
deps.resolver.allRecords["example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
"ns2.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testDomain] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
testNS2: {"A": {testIP}},
|
||||
}
|
||||
deps.portChecker.results["1.2.3.4:80"] = false
|
||||
deps.portChecker.results["1.2.3.4:443"] = false
|
||||
@@ -425,13 +436,13 @@ func TestNSChangeDetection(t *testing.T) {
|
||||
w.RunOnce(ctx)
|
||||
|
||||
deps.resolver.mu.Lock()
|
||||
deps.resolver.nsRecords["example.com"] = []string{
|
||||
"ns1.example.com.",
|
||||
deps.resolver.nsRecords[testDomain] = []string{
|
||||
testNS1,
|
||||
"ns3.example.com.",
|
||||
}
|
||||
deps.resolver.allRecords["example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
"ns3.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testDomain] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
"ns3.example.com.": {"A": {testIP}},
|
||||
}
|
||||
deps.resolver.mu.Unlock()
|
||||
|
||||
@@ -459,15 +470,15 @@ func TestRecordChangeDetection(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"93.184.216.34"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIPv4}},
|
||||
}
|
||||
deps.resolver.ipAddresses["www.example.com"] = []string{
|
||||
"93.184.216.34",
|
||||
deps.resolver.ipAddresses[testHost] = []string{
|
||||
testIPv4,
|
||||
}
|
||||
deps.portChecker.results["93.184.216.34:80"] = false
|
||||
deps.portChecker.results["93.184.216.34:443"] = false
|
||||
@@ -476,10 +487,10 @@ func TestRecordChangeDetection(t *testing.T) {
|
||||
w.RunOnce(ctx)
|
||||
|
||||
deps.resolver.mu.Lock()
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"93.184.216.35"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {"93.184.216.35"}},
|
||||
}
|
||||
deps.resolver.ipAddresses["www.example.com"] = []string{
|
||||
deps.resolver.ipAddresses[testHost] = []string{
|
||||
"93.184.216.35",
|
||||
}
|
||||
deps.resolver.mu.Unlock()
|
||||
@@ -501,24 +512,24 @@ func TestPortStateChange(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
}
|
||||
deps.resolver.ipAddresses["www.example.com"] = []string{
|
||||
"1.2.3.4",
|
||||
deps.resolver.ipAddresses[testHost] = []string{
|
||||
testIP,
|
||||
}
|
||||
deps.portChecker.results["1.2.3.4:80"] = true
|
||||
deps.portChecker.results["1.2.3.4:443"] = true
|
||||
deps.tlsChecker.certs["1.2.3.4:www.example.com"] = &tlscheck.CertificateInfo{
|
||||
CommonName: "www.example.com",
|
||||
Issuer: "DigiCert",
|
||||
CommonName: testHost,
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(90 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{
|
||||
"www.example.com",
|
||||
testHost,
|
||||
},
|
||||
}
|
||||
|
||||
@@ -541,24 +552,24 @@ func TestTLSExpiryWarning(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
}
|
||||
deps.resolver.ipAddresses["www.example.com"] = []string{
|
||||
"1.2.3.4",
|
||||
deps.resolver.ipAddresses[testHost] = []string{
|
||||
testIP,
|
||||
}
|
||||
deps.portChecker.results["1.2.3.4:80"] = true
|
||||
deps.portChecker.results["1.2.3.4:443"] = true
|
||||
deps.tlsChecker.certs["1.2.3.4:www.example.com"] = &tlscheck.CertificateInfo{
|
||||
CommonName: "www.example.com",
|
||||
Issuer: "DigiCert",
|
||||
CommonName: testHost,
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(3 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{
|
||||
"www.example.com",
|
||||
testHost,
|
||||
},
|
||||
}
|
||||
|
||||
@@ -592,25 +603,25 @@ func TestTLSExpiryWarningDedup(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
cfg.TLSInterval = 24 * time.Hour
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
}
|
||||
deps.resolver.ipAddresses["www.example.com"] = []string{
|
||||
"1.2.3.4",
|
||||
deps.resolver.ipAddresses[testHost] = []string{
|
||||
testIP,
|
||||
}
|
||||
deps.portChecker.results["1.2.3.4:80"] = true
|
||||
deps.portChecker.results["1.2.3.4:443"] = true
|
||||
deps.tlsChecker.certs["1.2.3.4:www.example.com"] = &tlscheck.CertificateInfo{
|
||||
CommonName: "www.example.com",
|
||||
Issuer: "DigiCert",
|
||||
CommonName: testHost,
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(3 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{
|
||||
"www.example.com",
|
||||
testHost,
|
||||
},
|
||||
}
|
||||
|
||||
@@ -647,17 +658,17 @@ func TestGracefulShutdown(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{"example.com"}
|
||||
cfg.Domains = []string{testDomain}
|
||||
cfg.DNSInterval = 100 * time.Millisecond
|
||||
cfg.TLSInterval = 100 * time.Millisecond
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.nsRecords["example.com"] = []string{
|
||||
"ns1.example.com.",
|
||||
deps.resolver.nsRecords[testDomain] = []string{
|
||||
testNS1,
|
||||
}
|
||||
deps.resolver.allRecords["example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testDomain] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
}
|
||||
deps.portChecker.results["1.2.3.4:80"] = false
|
||||
deps.portChecker.results["1.2.3.4:443"] = false
|
||||
@@ -687,13 +698,13 @@ func setupHostnameIP(
|
||||
hostname, ip string,
|
||||
) {
|
||||
deps.resolver.allRecords[hostname] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {ip}},
|
||||
testNS1: {"A": {ip}},
|
||||
}
|
||||
deps.portChecker.results[ip+":80"] = true
|
||||
deps.portChecker.results[ip+":443"] = true
|
||||
deps.tlsChecker.certs[ip+":"+hostname] = &tlscheck.CertificateInfo{
|
||||
CommonName: hostname,
|
||||
Issuer: "DigiCert",
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(90 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{hostname},
|
||||
}
|
||||
@@ -702,7 +713,7 @@ func setupHostnameIP(
|
||||
func updateHostnameIP(deps *testDeps, hostname, ip string) {
|
||||
deps.resolver.mu.Lock()
|
||||
deps.resolver.allRecords[hostname] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {ip}},
|
||||
testNS1: {"A": {ip}},
|
||||
}
|
||||
deps.resolver.mu.Unlock()
|
||||
|
||||
@@ -714,7 +725,7 @@ func updateHostnameIP(deps *testDeps, hostname, ip string) {
|
||||
deps.tlsChecker.mu.Lock()
|
||||
deps.tlsChecker.certs[ip+":"+hostname] = &tlscheck.CertificateInfo{
|
||||
CommonName: hostname,
|
||||
Issuer: "DigiCert",
|
||||
Issuer: testIssuer,
|
||||
NotAfter: time.Now().Add(90 * 24 * time.Hour),
|
||||
SubjectAlternativeNames: []string{hostname},
|
||||
}
|
||||
@@ -725,11 +736,11 @@ func TestDNSRunsBeforePortAndTLSChecks(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
setupHostnameIP(deps, "www.example.com", "10.0.0.1")
|
||||
setupHostnameIP(deps, testHost, "10.0.0.1")
|
||||
|
||||
ctx := t.Context()
|
||||
w.RunOnce(ctx)
|
||||
@@ -740,7 +751,7 @@ func TestDNSRunsBeforePortAndTLSChecks(t *testing.T) {
|
||||
}
|
||||
|
||||
// DNS changes to a new IP; port and TLS must pick it up.
|
||||
updateHostnameIP(deps, "www.example.com", "10.0.0.2")
|
||||
updateHostnameIP(deps, testHost, "10.0.0.2")
|
||||
|
||||
w.RunOnce(ctx)
|
||||
|
||||
@@ -760,8 +771,8 @@ func TestSendTestNotification_Enabled(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{"example.com"}
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Domains = []string{testDomain}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
cfg.SendTestNotification = true
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
@@ -786,8 +797,8 @@ func TestSendTestNotification_ViaRun(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{"example.com"}
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Domains = []string{testDomain}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
cfg.SendTestNotification = true
|
||||
cfg.DNSInterval = 24 * time.Hour
|
||||
cfg.TLSInterval = 24 * time.Hour
|
||||
@@ -833,8 +844,8 @@ func TestSendTestNotification_Disabled(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Domains = []string{"example.com"}
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Domains = []string{testDomain}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
cfg.SendTestNotification = false
|
||||
cfg.DNSInterval = 24 * time.Hour
|
||||
cfg.TLSInterval = 24 * time.Hour
|
||||
@@ -871,16 +882,16 @@ func TestNSFailureAndRecovery(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := defaultTestConfig(t)
|
||||
cfg.Hostnames = []string{"www.example.com"}
|
||||
cfg.Hostnames = []string{testHost}
|
||||
|
||||
w, deps := newTestWatcher(t, cfg)
|
||||
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
"ns2.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
testNS2: {"A": {testIP}},
|
||||
}
|
||||
deps.resolver.ipAddresses["www.example.com"] = []string{
|
||||
"1.2.3.4",
|
||||
deps.resolver.ipAddresses[testHost] = []string{
|
||||
testIP,
|
||||
}
|
||||
deps.portChecker.results["1.2.3.4:80"] = false
|
||||
deps.portChecker.results["1.2.3.4:443"] = false
|
||||
@@ -890,8 +901,8 @@ func TestNSFailureAndRecovery(t *testing.T) {
|
||||
w.RunOnce(ctx)
|
||||
|
||||
deps.resolver.mu.Lock()
|
||||
deps.resolver.allRecords["www.example.com"] = map[string]map[string][]string{
|
||||
"ns1.example.com.": {"A": {"1.2.3.4"}},
|
||||
deps.resolver.allRecords[testHost] = map[string]map[string][]string{
|
||||
testNS1: {"A": {testIP}},
|
||||
}
|
||||
deps.resolver.mu.Unlock()
|
||||
|
||||
|
||||
@@ -9,9 +9,9 @@ set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
# Pinned versions, 2026-07-07 (same pins as the Dockerfile)
|
||||
# golangci-lint v2.10.1
|
||||
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@5d1e709b7be35cb2025444e19de266b056b7b7ee"
|
||||
# Pinned versions, 2026-08-07 (same pins as the Dockerfile)
|
||||
# golangci-lint v2.12.2
|
||||
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5"
|
||||
# goimports v0.42.0
|
||||
GOIMPORTS_REF="golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user