1 Commits

Author SHA1 Message Date
584b5f5b39 build: update golangci-lint to v2.12.2 with commit-pinned installs
All checks were successful
check / check (push) Successful in 1m0s
Pin golangci-lint to commit c0d3ddc9cf3faa61a4e378e879ece580256d76e5
(v2.12.2) in Dockerfile and script/bootstrap. Fix the goconst findings
the new version reports under the unchanged canonical .golangci.yml by
extracting shared test fixture constants and a statusError constant in
the watcher.
2026-08-07 20:21:36 +00:00
12 changed files with 634 additions and 518 deletions

View File

@@ -4,8 +4,8 @@ FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4
RUN apk add --no-cache git make gcc musl-dev binutils-gold
# golangci-lint v2.10.1
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@5d1e709b7be35cb2025444e19de266b056b7b7ee
# golangci-lint v2.12.2, 2026-08-07
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5
# goimports v0.42.0
RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0

View File

@@ -2,10 +2,8 @@
## DNS Resolution Tests
All tests that involve DNS resolution — in every package, including
consumers of the resolver such as the watcher — **MUST** use live
queries against real DNS servers. No mocking, faking, or stubbing of
DNS at any layer is permitted.
All resolver tests **MUST** use live queries against real DNS servers.
No mocking of the DNS client layer is permitted.
### Rationale
@@ -14,8 +12,6 @@ the full delegation chain. Mocked responses cannot faithfully represent
the variety of real-world DNS behavior (truncation, referrals, glue
records, DNSSEC, varied response times, EDNS, etc.). Testing against
real servers ensures the resolver works correctly in production.
Robustness comes from handling real-world DNS behavior with tolerant
assertions and sensible timeouts, not from mocks.
### Constraints
@@ -28,14 +24,11 @@ assertions and sensible timeouts, not from mocks.
- Flaky failures from transient network issues are acceptable and
should be investigated as potential resolver bugs, not papered over
with mocks or skip flags
- Watcher change-detection tests seed a synthetic *previous state*
and compare it against fresh live lookups; the DNS side is never
faked
### What NOT to do
- **Do not mock `DNSClient`**, the watcher's `DNSResolver` interface,
or any other DNS abstraction — in any package, for any reason
- **Do not mock `DNSClient`** for resolver tests (the mock constructor
exists for unit-testing other packages that consume the resolver)
- **Do not add `-short` flags** to skip slow tests
- **Do not increase `-timeout`** to hide hanging queries
- **Do not modify linter configuration** to suppress findings

27
TODO.md
View File

@@ -14,10 +14,7 @@ pre-1.0. No git tags. Core resolver work in flight on feature/resolver
(dirty: internal/resolver/resolver_test.go). Local checkout has diverged
from origin: origin/main is 8 commits ahead (watcher orchestrator,
unified TARGETS) and origin/feature/resolver already contains the full
iterative resolver implementation. DNS mocking is banned in this repo
(see `TESTING.md`): all tests use live DNS only. The hermetic mocked
tests previously noted on `feature/resolver` are gone from its current
tip, which carries a live-DNS suite against `*.dns.sneak.cloud`.
iterative resolver implementation with hermetic mocked tests.
# Next Step
@@ -28,15 +25,13 @@ confirm make check still passes.
# Completed Steps
- 2026-08-07: DNS mocking removed from the entire test suite; watcher
tests now drive the real iterative resolver against live DNS and
`TESTING.md` bans DNS mocks in every package (`remove-dns-mocking`
branch)
- 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs
in `Dockerfile` and `script/bootstrap`); fixed the resulting
`goconst` findings. `.golangci.yml` unchanged (canonical)
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
Makefile shims, README Entrypoints section
- 2026-02-20: iterative DNS resolver implemented; tests made hermetic
with mocked DNS (origin/feature/resolver, unmerged; superseded — DNS
mocking is banned, see `TESTING.md`)
with mocked DNS (origin/feature/resolver, unmerged)
- 2026-02-20: CI actions and go install refs pinned to commit SHAs;
Gitea Actions workflow for make check (origin/ci/make-check, unmerged)
- 2026-02-20: watcher monitoring orchestrator merged to main (#8)
@@ -63,9 +58,8 @@ Branch reconciliation:
- Sync local checkout with origin: local main is 8 commits behind
origin/main; local feature/resolver has diverged from
origin/feature/resolver, which already implements the resolver
- Merge in-flight branches to main once green: feature/resolver
(confirm its tests remain live-DNS — DNS mocking is banned, see
`TESTING.md`), ci/make-check, feature/portcheck-implementation,
- Merge in-flight branches to main once green: feature/resolver,
ci/make-check, feature/portcheck-implementation,
feature/tlscheck-implementation
Resolver (plan from untracked TODO.md; largely implemented on
@@ -149,7 +143,6 @@ Infrastructure notes (from untracked TODO.md):
- Module path sneak.berlin/go/dnswatcher differs from the git.eeqj.de
remote intentionally; do not "fix" it
- Dependencies: github.com/miekg/dns, golang.org/x/net/publicsuffix
- Resolver tests originally used live DNS against `*.dns.sneak.cloud`
(required records documented in the test file header); `main` now
tests against live public DNS. DNS mocking is banned (see
`TESTING.md`); never reintroduce hermetic mocked DNS tests
- Resolver tests originally used live DNS against *.dns.sneak.cloud
(required records documented in the test file header); origin now has
mocked hermetic tests, keep them hermetic

View File

@@ -25,6 +25,18 @@ const (
colorDefault = "#6c757d"
)
// Priority and fixture values shared across tests.
const (
prioError = "error"
prioWarning = "warning"
prioInfo = "info"
prioSuccess = "success"
prioUnknown = "unknown"
ntfyUrgent = "urgent"
ntfyDefault = "default"
testHost = "example.com"
)
// errSimulated is a static error for transport failures.
var errSimulated = errors.New("simulated transport failure")
@@ -101,13 +113,13 @@ func TestNtfyPriority(t *testing.T) {
input string
want string
}{
{"error", "urgent"},
{"warning", "high"},
{"success", "default"},
{"info", "low"},
{"", "default"},
{"unknown", "default"},
{"critical", "default"},
{prioError, ntfyUrgent},
{prioWarning, "high"},
{prioSuccess, ntfyDefault},
{prioInfo, "low"},
{"", ntfyDefault},
{prioUnknown, ntfyDefault},
{"critical", ntfyDefault},
}
for _, tc := range cases {
@@ -134,12 +146,12 @@ func TestSlackColor(t *testing.T) {
input string
want string
}{
{"error", colorError},
{"warning", colorWarning},
{"success", colorSuccess},
{"info", colorInfo},
{prioError, colorError},
{prioWarning, colorWarning},
{prioSuccess, colorSuccess},
{prioInfo, colorInfo},
{"", colorDefault},
{"unknown", colorDefault},
{prioUnknown, colorDefault},
{"critical", colorDefault},
}
@@ -165,7 +177,7 @@ func TestNewRequest(t *testing.T) {
target := &url.URL{
Scheme: "https",
Host: "example.com",
Host: testHost,
Path: "/webhook",
}
body := bytes.NewBufferString("hello")
@@ -187,9 +199,9 @@ func TestNewRequest(t *testing.T) {
)
}
if req.Host != "example.com" {
if req.Host != testHost {
t.Errorf(
"Host = %q, want %q", req.Host, "example.com",
"Host = %q, want %q", req.Host, testHost,
)
}
@@ -217,7 +229,7 @@ func TestNewRequestPreservesContext(t *testing.T) {
ctxKey("k"),
"v",
)
target := &url.URL{Scheme: "https", Host: "example.com"}
target := &url.URL{Scheme: "https", Host: testHost}
req := notify.NewRequestForTest(
ctx, http.MethodGet, target, http.NoBody,
@@ -289,10 +301,10 @@ func TestSendNtfyHeaders(t *testing.T) {
)
}
if captured.priority != "urgent" {
if captured.priority != ntfyUrgent {
t.Errorf(
"Priority header = %q, want %q",
captured.priority, "urgent",
captured.priority, ntfyUrgent,
)
}
@@ -311,10 +323,10 @@ func TestSendNtfyAllPriorities(t *testing.T) {
input string
want string
}{
{"error", "urgent"},
{"warning", "high"},
{"success", "default"},
{"info", "low"},
{prioError, ntfyUrgent},
{prioWarning, "high"},
{prioSuccess, ntfyDefault},
{prioInfo, "low"},
}
for _, tc := range priorities {
@@ -550,11 +562,11 @@ func TestSendSlackAllColors(t *testing.T) {
priority string
want string
}{
{"error", colorError},
{"warning", colorWarning},
{"success", colorSuccess},
{"info", colorInfo},
{"unknown", colorDefault},
{prioError, colorError},
{prioWarning, colorWarning},
{prioSuccess, colorSuccess},
{prioInfo, colorInfo},
{prioUnknown, colorDefault},
}
for _, tc := range colors {

View File

@@ -29,14 +29,14 @@ func TestAlertHistoryAddAndRecent(t *testing.T) {
Timestamp: now.Add(-2 * time.Minute),
Title: "first",
Message: "msg1",
Priority: "info",
Priority: prioInfo,
})
h.Add(notify.AlertEntry{
Timestamp: now.Add(-1 * time.Minute),
Title: "second",
Message: "msg2",
Priority: "warning",
Priority: prioWarning,
})
entries := h.Recent()

View File

@@ -7,8 +7,8 @@ import (
"github.com/miekg/dns"
)
// DNSClient abstracts DNS wire-protocol exchanges over a single
// transport, letting the resolver switch between UDP and TCP.
// DNSClient abstracts DNS wire-protocol exchanges so the resolver
// can be tested without hitting real nameservers.
type DNSClient interface {
ExchangeContext(
ctx context.Context,

View File

@@ -67,4 +67,17 @@ func NewFromLogger(log *slog.Logger) *Resolver {
}
}
// NewFromLoggerWithClient creates a Resolver with a custom DNS
// client, useful for testing with mock DNS responses.
func NewFromLoggerWithClient(
log *slog.Logger,
client DNSClient,
) *Resolver {
return &Resolver{
log: log,
client: client,
tcp: client,
}
}
// Method implementations are in iterative.go.

View File

@@ -10,6 +10,7 @@ import (
"testing"
"time"
"github.com/miekg/dns"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
@@ -623,41 +624,58 @@ func TestQueryAllNameservers_ContextCanceled(t *testing.T) {
}
// ----------------------------------------------------------------
// Unreachable nameserver tests
// Timeout tests
// ----------------------------------------------------------------
func TestQueryNameserverIP_UnreachableServer(t *testing.T) {
func TestQueryNameserverIP_Timeout(t *testing.T) {
t.Parallel()
r := newTestResolver(t)
log := slog.New(slog.NewTextHandler(
os.Stderr,
&slog.HandlerOptions{Level: slog.LevelDebug},
))
r := resolver.NewFromLoggerWithClient(
log, &timeoutClient{},
)
ctx, cancel := context.WithTimeout(
context.Background(), 10*time.Second,
)
t.Cleanup(cancel)
// 192.0.2.1 is an RFC 5737 documentation address: no
// nameserver can exist there. Depending on the network
// path the queries either time out (silent drop) or fail
// fast (ICMP unreachable), so accept any non-OK status;
// the resolver must return a classified response with no
// records rather than an error or a hang.
// Query any IP — the client always returns a timeout error.
resp, err := r.QueryNameserverIP(
ctx, "unreachable.test.", "192.0.2.1",
"example.com",
)
require.NoError(t, err)
assert.NotEqual(t, resolver.StatusOK, resp.Status)
totalRecords := 0
for _, values := range resp.Records {
totalRecords += len(values)
}
assert.Zero(t, totalRecords)
assert.Equal(t, resolver.StatusTimeout, resp.Status)
assert.NotEmpty(t, resp.Error)
}
// timeoutClient simulates DNS timeout errors for testing.
type timeoutClient struct{}
func (c *timeoutClient) ExchangeContext(
_ context.Context,
_ *dns.Msg,
_ string,
) (*dns.Msg, time.Duration, error) {
return nil, 0, &net.OpError{
Op: "read",
Net: "udp",
Err: &timeoutError{},
}
}
type timeoutError struct{}
func (e *timeoutError) Error() string { return "i/o timeout" }
func (e *timeoutError) Timeout() bool { return true }
func (e *timeoutError) Temporary() bool { return true }
func TestResolveIPAddresses_ContextCanceled(t *testing.T) {
t.Parallel()

View File

@@ -13,6 +13,16 @@ import (
const testHostname = "www.example.com"
// Shared fixture values used across tests.
const (
testNS1 = "ns1.example.com."
testNS2 = "ns2.example.com."
testAltNS1 = "ns1.test.com."
testIPv4 = "93.184.216.34"
testIP = "1.2.3.4"
statusError = "error"
)
// populateState fills a State with representative test data across all categories.
func populateState(t *testing.T, s *state.State) {
t.Helper()
@@ -20,7 +30,7 @@ func populateState(t *testing.T, s *state.State) {
now := time.Now().UTC().Truncate(time.Second)
s.SetDomainState("example.com", &state.DomainState{
Nameservers: []string{"ns1.example.com.", "ns2.example.com."},
Nameservers: []string{testNS1, testNS2},
LastChecked: now,
})
@@ -31,17 +41,17 @@ func populateState(t *testing.T, s *state.State) {
s.SetHostnameState(testHostname, &state.HostnameState{
RecordsByNameserver: map[string]*state.NameserverRecordState{
"ns1.example.com.": {
testNS1: {
Records: map[string][]string{
"A": {"93.184.216.34"},
"A": {testIPv4},
"AAAA": {"2606:2800:220:1:248:1893:25c8:1946"},
},
Status: "ok",
LastChecked: now,
},
"ns2.example.com.": {
testNS2: {
Records: map[string][]string{
"A": {"93.184.216.34"},
"A": {testIPv4},
},
Status: "ok",
LastChecked: now,
@@ -152,13 +162,13 @@ func TestSaveLoadRoundTrip_Hostnames(t *testing.T) {
func verifyNS1Records(t *testing.T, hn *state.HostnameState) {
t.Helper()
ns1, ok := hn.RecordsByNameserver["ns1.example.com."]
ns1, ok := hn.RecordsByNameserver[testNS1]
if !ok {
t.Fatal("missing nameserver ns1.example.com.")
}
aRecords := ns1.Records["A"]
if len(aRecords) != 1 || aRecords[0] != "93.184.216.34" {
if len(aRecords) != 1 || aRecords[0] != testIPv4 {
t.Errorf("ns1 A records: got %v", aRecords)
}
@@ -653,7 +663,7 @@ func TestDomainState_GetSet(t *testing.T) {
now := time.Now().UTC().Truncate(time.Second)
ds := &state.DomainState{
Nameservers: []string{"ns1.test.com."},
Nameservers: []string{testAltNS1},
LastChecked: now,
}
@@ -664,7 +674,7 @@ func TestDomainState_GetSet(t *testing.T) {
t.Fatal("expected true for existing domain")
}
if len(got.Nameservers) != 1 || got.Nameservers[0] != "ns1.test.com." {
if len(got.Nameservers) != 1 || got.Nameservers[0] != testAltNS1 {
t.Errorf("nameservers: got %v", got.Nameservers)
}
@@ -674,7 +684,7 @@ func TestDomainState_GetSet(t *testing.T) {
// Overwrite.
ds2 := &state.DomainState{
Nameservers: []string{"ns1.test.com.", "ns2.test.com."},
Nameservers: []string{testAltNS1, "ns2.test.com."},
LastChecked: now.Add(time.Hour),
}
@@ -704,8 +714,8 @@ func TestHostnameState_GetSet(t *testing.T) {
now := time.Now().UTC().Truncate(time.Second)
hs := &state.HostnameState{
RecordsByNameserver: map[string]*state.NameserverRecordState{
"ns1.example.com.": {
Records: map[string][]string{"A": {"1.2.3.4"}},
testNS1: {
Records: map[string][]string{"A": {testIP}},
Status: "ok",
LastChecked: now,
},
@@ -720,7 +730,7 @@ func TestHostnameState_GetSet(t *testing.T) {
t.Fatal("expected true for existing hostname")
}
nsState, ok := got.RecordsByNameserver["ns1.example.com."]
nsState, ok := got.RecordsByNameserver[testNS1]
if !ok {
t.Fatal("missing nameserver entry")
}
@@ -730,7 +740,7 @@ func TestHostnameState_GetSet(t *testing.T) {
}
aRecords := nsState.Records["A"]
if len(aRecords) != 1 || aRecords[0] != "1.2.3.4" {
if len(aRecords) != 1 || aRecords[0] != testIP {
t.Errorf("A records: got %v", aRecords)
}
}
@@ -869,7 +879,7 @@ func TestCertificateState_ErrorField(t *testing.T) {
now := time.Now().UTC().Truncate(time.Second)
cs := &state.CertificateState{
Status: "error",
Status: statusError,
Error: "connection refused",
LastChecked: now,
}
@@ -893,8 +903,8 @@ func TestCertificateState_ErrorField(t *testing.T) {
t.Fatal("missing certificate after load")
}
if got.Status != "error" {
t.Errorf("status: got %q, want %q", got.Status, "error")
if got.Status != statusError {
t.Errorf("status: got %q, want %q", got.Status, statusError)
}
if got.Error != "connection refused" {
@@ -912,9 +922,9 @@ func TestHostnameState_ErrorField(t *testing.T) {
now := time.Now().UTC().Truncate(time.Second)
hs := &state.HostnameState{
RecordsByNameserver: map[string]*state.NameserverRecordState{
"ns1.example.com.": {
testNS1: {
Records: nil,
Status: "error",
Status: statusError,
Error: "SERVFAIL",
LastChecked: now,
},
@@ -941,9 +951,9 @@ func TestHostnameState_ErrorField(t *testing.T) {
t.Fatal("missing hostname after load")
}
nsState := got.RecordsByNameserver["ns1.example.com."]
if nsState.Status != "error" {
t.Errorf("status: got %q, want %q", nsState.Status, "error")
nsState := got.RecordsByNameserver[testNS1]
if nsState.Status != statusError {
t.Errorf("status: got %q, want %q", nsState.Status, statusError)
}
if nsState.Error != "SERVFAIL" {
@@ -1085,7 +1095,7 @@ func runConcurrentOps(s *state.State, key string, now time.Time) {
s.SetHostnameState(key+".example.com", &state.HostnameState{
RecordsByNameserver: map[string]*state.NameserverRecordState{
"ns1.test.": {
Records: map[string][]string{"A": {"1.2.3.4"}},
Records: map[string][]string{"A": {testIP}},
Status: "ok",
LastChecked: now,
},

View File

@@ -26,6 +26,9 @@ const tlsPort = 443
// hoursPerDay converts days to hours for duration calculations.
const hoursPerDay = 24
// statusError is the status value recorded for failed checks.
const statusError = "error"
// Params contains dependencies for Watcher.
type Params struct {
fx.In
@@ -421,7 +424,7 @@ func (w *Watcher) detectNSDisappearances(
for ns := range current {
prevNS, ok := prev.RecordsByNameserver[ns]
if !ok || prevNS.Status != "error" {
if !ok || prevNS.Status != statusError {
continue
}
@@ -721,7 +724,7 @@ func (w *Watcher) handleTLSError(
w.state.SetCertificateState(
certKey, &state.CertificateState{
Status: "error",
Status: statusError,
Error: err.Error(),
LastChecked: now,
},
@@ -760,7 +763,7 @@ func (w *Watcher) detectTLSChanges(
prev *state.CertificateState,
cert *tlscheck.CertificateInfo,
) {
if prev.Status == "error" {
if prev.Status == statusError {
msg := fmt.Sprintf(
"Host: %s\nIP: %s\nTLS recovered",
hostname, ip,

File diff suppressed because it is too large Load Diff

View File

@@ -9,9 +9,9 @@ set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
# Pinned versions, 2026-07-07 (same pins as the Dockerfile)
# golangci-lint v2.10.1
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@5d1e709b7be35cb2025444e19de266b056b7b7ee"
# Pinned versions, 2026-08-07 (same pins as the Dockerfile)
# golangci-lint v2.12.2
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5"
# goimports v0.42.0
GOIMPORTS_REF="golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0"