1 Commits

Author SHA1 Message Date
584b5f5b39 build: update golangci-lint to v2.12.2 with commit-pinned installs
All checks were successful
check / check (push) Successful in 1m0s
Pin golangci-lint to commit c0d3ddc9cf3faa61a4e378e879ece580256d76e5
(v2.12.2) in Dockerfile and script/bootstrap. Fix the goconst findings
the new version reports under the unchanged canonical .golangci.yml by
extracting shared test fixture constants and a statusError constant in
the watcher.
2026-08-07 20:21:36 +00:00
13 changed files with 699 additions and 632 deletions

View File

@@ -1,9 +1,5 @@
version: "2" version: "2"
# Config schema uses the golangci-lint v2 layout (settings live under
# linters.settings, not top-level linters-settings) so that the
# thresholds below are actually applied by golangci-lint >= v2.
run: run:
timeout: 5m timeout: 5m
modules-download-mode: readonly modules-download-mode: readonly
@@ -18,17 +14,19 @@ linters:
- wsl # Deprecated, replaced by wsl_v5 - wsl # Deprecated, replaced by wsl_v5
- wrapcheck # Too verbose for internal packages - wrapcheck # Too verbose for internal packages
- varnamelen # Short names like db, id are idiomatic Go - varnamelen # Short names like db, id are idiomatic Go
settings:
lll: linters-settings:
line-length: 88 lll:
funlen: line-length: 88
lines: 80 funlen:
statements: 50 lines: 80
cyclop: statements: 50
max-complexity: 15 cyclop:
dupl: max-complexity: 15
threshold: 100 dupl:
threshold: 100
issues: issues:
exclude-use-default: false
max-issues-per-linter: 0 max-issues-per-linter: 0
max-same-issues: 0 max-same-issues: 0

View File

@@ -17,26 +17,6 @@ without requiring an external database.
--- ---
## No DNS mocking. Ever.
**DNS is never mocked in this project — not in tests, not anywhere else.**
No mock resolvers, no fake DNS servers, no stubbed lookups.
dnswatcher's entire purpose is correct behavior against the real DNS.
Tests exercise real iterative resolution against live nameservers by
design; a test suite that passes against a mock proves nothing about the
one thing this program exists to do.
When live tests are flaky, that is a robustness problem, and it gets
fixed with robustness: retries with backoff, querying multiple
independent nameservers, longer timeouts — or explicit opt-in gating
decided by the project owner. Never with mocks.
Contributions that introduce mocked, faked, or stubbed DNS will be
rejected.
---
## Features ## Features
### DNS Domain Monitoring (Apex Domains) ### DNS Domain Monitoring (Apex Domains)

View File

@@ -2,10 +2,8 @@
## DNS Resolution Tests ## DNS Resolution Tests
All tests that involve DNS resolution — in every package, including All resolver tests **MUST** use live queries against real DNS servers.
consumers of the resolver such as the watcher — **MUST** use live No mocking of the DNS client layer is permitted.
queries against real DNS servers. No mocking, faking, or stubbing of
DNS at any layer is permitted.
### Rationale ### Rationale
@@ -14,8 +12,6 @@ the full delegation chain. Mocked responses cannot faithfully represent
the variety of real-world DNS behavior (truncation, referrals, glue the variety of real-world DNS behavior (truncation, referrals, glue
records, DNSSEC, varied response times, EDNS, etc.). Testing against records, DNSSEC, varied response times, EDNS, etc.). Testing against
real servers ensures the resolver works correctly in production. real servers ensures the resolver works correctly in production.
Robustness comes from handling real-world DNS behavior with tolerant
assertions and sensible timeouts, not from mocks.
### Constraints ### Constraints
@@ -28,14 +24,11 @@ assertions and sensible timeouts, not from mocks.
- Flaky failures from transient network issues are acceptable and - Flaky failures from transient network issues are acceptable and
should be investigated as potential resolver bugs, not papered over should be investigated as potential resolver bugs, not papered over
with mocks or skip flags with mocks or skip flags
- Watcher change-detection tests seed a synthetic *previous state*
and compare it against fresh live lookups; the DNS side is never
faked
### What NOT to do ### What NOT to do
- **Do not mock `DNSClient`**, the watcher's `DNSResolver` interface, - **Do not mock `DNSClient`** for resolver tests (the mock constructor
or any other DNS abstraction — in any package, for any reason exists for unit-testing other packages that consume the resolver)
- **Do not add `-short` flags** to skip slow tests - **Do not add `-short` flags** to skip slow tests
- **Do not increase `-timeout`** to hide hanging queries - **Do not increase `-timeout`** to hide hanging queries
- **Do not modify linter configuration** to suppress findings - **Do not modify linter configuration** to suppress findings

33
TODO.md
View File

@@ -14,10 +14,7 @@ pre-1.0. No git tags. Core resolver work in flight on feature/resolver
(dirty: internal/resolver/resolver_test.go). Local checkout has diverged (dirty: internal/resolver/resolver_test.go). Local checkout has diverged
from origin: origin/main is 8 commits ahead (watcher orchestrator, from origin: origin/main is 8 commits ahead (watcher orchestrator,
unified TARGETS) and origin/feature/resolver already contains the full unified TARGETS) and origin/feature/resolver already contains the full
iterative resolver implementation. DNS mocking is banned in this repo iterative resolver implementation with hermetic mocked tests.
(see `TESTING.md`): all tests use live DNS only. The hermetic mocked
tests previously noted on `feature/resolver` are gone from its current
tip, which carries a live-DNS suite against `*.dns.sneak.cloud`.
# Next Step # Next Step
@@ -28,23 +25,13 @@ confirm make check still passes.
# Completed Steps # Completed Steps
- 2026-08-07: DNS mocking removed from the entire test suite; watcher
tests now drive the real iterative resolver against live DNS and
`TESTING.md` bans DNS mocks in every package (`remove-dns-mocking`
branch)
- 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs - 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs
in `Dockerfile` and `script/bootstrap`); `.golangci.yml` set to the in `Dockerfile` and `script/bootstrap`); fixed the resulting
org-standard v2-schema config used across the org's repos `goconst` findings. `.golangci.yml` unchanged (canonical)
(owner-authorized; same file is being landed as canonical via prompts
PR #24), with settings under `linters.settings` so the
lll/funlen/cyclop/dupl thresholds apply; fixed the resulting
`goconst`, `dupl`, and `lll` findings; the informational `gomodguard`
deprecation warning under this config is accepted
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, - 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
Makefile shims, README Entrypoints section Makefile shims, README Entrypoints section
- 2026-02-20: iterative DNS resolver implemented; tests made hermetic - 2026-02-20: iterative DNS resolver implemented; tests made hermetic
with mocked DNS (origin/feature/resolver, unmerged; superseded — DNS with mocked DNS (origin/feature/resolver, unmerged)
mocking is banned, see `TESTING.md`)
- 2026-02-20: CI actions and go install refs pinned to commit SHAs; - 2026-02-20: CI actions and go install refs pinned to commit SHAs;
Gitea Actions workflow for make check (origin/ci/make-check, unmerged) Gitea Actions workflow for make check (origin/ci/make-check, unmerged)
- 2026-02-20: watcher monitoring orchestrator merged to main (#8) - 2026-02-20: watcher monitoring orchestrator merged to main (#8)
@@ -71,9 +58,8 @@ Branch reconciliation:
- Sync local checkout with origin: local main is 8 commits behind - Sync local checkout with origin: local main is 8 commits behind
origin/main; local feature/resolver has diverged from origin/main; local feature/resolver has diverged from
origin/feature/resolver, which already implements the resolver origin/feature/resolver, which already implements the resolver
- Merge in-flight branches to main once green: feature/resolver - Merge in-flight branches to main once green: feature/resolver,
(confirm its tests remain live-DNS — DNS mocking is banned, see ci/make-check, feature/portcheck-implementation,
`TESTING.md`), ci/make-check, feature/portcheck-implementation,
feature/tlscheck-implementation feature/tlscheck-implementation
Resolver (plan from untracked TODO.md; largely implemented on Resolver (plan from untracked TODO.md; largely implemented on
@@ -157,7 +143,6 @@ Infrastructure notes (from untracked TODO.md):
- Module path sneak.berlin/go/dnswatcher differs from the git.eeqj.de - Module path sneak.berlin/go/dnswatcher differs from the git.eeqj.de
remote intentionally; do not "fix" it remote intentionally; do not "fix" it
- Dependencies: github.com/miekg/dns, golang.org/x/net/publicsuffix - Dependencies: github.com/miekg/dns, golang.org/x/net/publicsuffix
- Resolver tests originally used live DNS against `*.dns.sneak.cloud` - Resolver tests originally used live DNS against *.dns.sneak.cloud
(required records documented in the test file header); `main` now (required records documented in the test file header); origin now has
tests against live public DNS. DNS mocking is banned (see mocked hermetic tests, keep them hermetic
`TESTING.md`); never reintroduce hermetic mocked DNS tests

View File

@@ -17,33 +17,13 @@ func TestClassifyDNSName(t *testing.T) {
}{ }{
{name: "apex domain simple", input: "example.com", want: config.DNSNameTypeDomain}, {name: "apex domain simple", input: "example.com", want: config.DNSNameTypeDomain},
{name: "hostname simple", input: "www.example.com", want: config.DNSNameTypeHostname}, {name: "hostname simple", input: "www.example.com", want: config.DNSNameTypeHostname},
{ {name: "apex domain multi-part TLD", input: "example.co.uk", want: config.DNSNameTypeDomain},
name: "apex domain multi-part TLD", {name: "hostname multi-part TLD", input: "api.example.co.uk", want: config.DNSNameTypeHostname},
input: "example.co.uk",
want: config.DNSNameTypeDomain,
},
{
name: "hostname multi-part TLD",
input: "api.example.co.uk",
want: config.DNSNameTypeHostname,
},
{name: "public suffix itself", input: "co.uk", wantErr: true}, {name: "public suffix itself", input: "co.uk", wantErr: true},
{name: "empty string", input: "", wantErr: true}, {name: "empty string", input: "", wantErr: true},
{ {name: "deeply nested hostname", input: "a.b.c.example.com", want: config.DNSNameTypeHostname},
name: "deeply nested hostname", {name: "trailing dot stripped", input: "example.com.", want: config.DNSNameTypeDomain},
input: "a.b.c.example.com", {name: "uppercase normalized", input: "WWW.Example.COM", want: config.DNSNameTypeHostname},
want: config.DNSNameTypeHostname,
},
{
name: "trailing dot stripped",
input: "example.com.",
want: config.DNSNameTypeDomain,
},
{
name: "uppercase normalized",
input: "WWW.Example.COM",
want: config.DNSNameTypeHostname,
},
} }
for _, tt := range tests { for _, tt := range tests {

View File

@@ -25,20 +25,18 @@ const (
colorDefault = "#6c757d" colorDefault = "#6c757d"
) )
// Priority strings used across multiple tests. // Priority and fixture values shared across tests.
const ( const (
prioError = "error" prioError = "error"
prioWarning = "warning" prioWarning = "warning"
prioSuccess = "success"
prioInfo = "info" prioInfo = "info"
prioSuccess = "success"
prioUnknown = "unknown" prioUnknown = "unknown"
prioDefault = "default" ntfyUrgent = "urgent"
prioUrgent = "urgent" ntfyDefault = "default"
testHost = "example.com"
) )
// testHost is the hostname used in request construction tests.
const testHost = "example.com"
// errSimulated is a static error for transport failures. // errSimulated is a static error for transport failures.
var errSimulated = errors.New("simulated transport failure") var errSimulated = errors.New("simulated transport failure")
@@ -115,13 +113,13 @@ func TestNtfyPriority(t *testing.T) {
input string input string
want string want string
}{ }{
{prioError, prioUrgent}, {prioError, ntfyUrgent},
{prioWarning, "high"}, {prioWarning, "high"},
{prioSuccess, prioDefault}, {prioSuccess, ntfyDefault},
{prioInfo, "low"}, {prioInfo, "low"},
{"", prioDefault}, {"", ntfyDefault},
{prioUnknown, prioDefault}, {prioUnknown, ntfyDefault},
{"critical", prioDefault}, {"critical", ntfyDefault},
} }
for _, tc := range cases { for _, tc := range cases {
@@ -303,10 +301,10 @@ func TestSendNtfyHeaders(t *testing.T) {
) )
} }
if captured.priority != prioUrgent { if captured.priority != ntfyUrgent {
t.Errorf( t.Errorf(
"Priority header = %q, want %q", "Priority header = %q, want %q",
captured.priority, prioUrgent, captured.priority, ntfyUrgent,
) )
} }
@@ -325,9 +323,9 @@ func TestSendNtfyAllPriorities(t *testing.T) {
input string input string
want string want string
}{ }{
{prioError, prioUrgent}, {prioError, ntfyUrgent},
{prioWarning, "high"}, {prioWarning, "high"},
{prioSuccess, prioDefault}, {prioSuccess, ntfyDefault},
{prioInfo, "low"}, {prioInfo, "low"},
} }
@@ -370,69 +368,56 @@ func TestSendNtfyAllPriorities(t *testing.T) {
} }
} }
// assertSendStatusError verifies that send returns an error func TestSendNtfyClientError(t *testing.T) {
// wrapping wantErr when the server responds with status. t.Parallel()
func assertSendStatusError(
t *testing.T,
status int,
wantErr error,
send func(*notify.Service, *url.URL) error,
) {
t.Helper()
srv := httptest.NewServer( srv := httptest.NewServer(
http.HandlerFunc( http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) { func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(status) w.WriteHeader(http.StatusForbidden)
}), }),
) )
defer srv.Close() defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport) svc := notify.NewTestService(srv.Client().Transport)
target, _ := url.Parse(srv.URL) topicURL, _ := url.Parse(srv.URL)
err := send(svc, target) err := svc.SendNtfy(
context.Background(), topicURL, "t", "m", "info",
)
if err == nil { if err == nil {
t.Fatalf("expected error for %d response", status) t.Fatal("expected error for 403 response")
} }
if !errors.Is(err, wantErr) { if !errors.Is(err, notify.ErrNtfyFailed) {
t.Errorf("error = %v, want %v", err, wantErr) t.Errorf("error = %v, want ErrNtfyFailed", err)
} }
} }
func sendNtfyInfo(
svc *notify.Service, target *url.URL,
) error {
return svc.SendNtfy(
context.Background(), target, "t", "m", prioInfo,
)
}
func sendSlackInfo(
svc *notify.Service, target *url.URL,
) error {
return svc.SendSlack(
context.Background(), target, "t", "m", prioInfo,
)
}
func TestSendNtfyClientError(t *testing.T) {
t.Parallel()
assertSendStatusError(
t, http.StatusForbidden,
notify.ErrNtfyFailed, sendNtfyInfo,
)
}
func TestSendNtfyServerError(t *testing.T) { func TestSendNtfyServerError(t *testing.T) {
t.Parallel() t.Parallel()
assertSendStatusError( srv := httptest.NewServer(
t, http.StatusInternalServerError, http.HandlerFunc(
notify.ErrNtfyFailed, sendNtfyInfo, func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusInternalServerError)
}),
) )
defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport)
topicURL, _ := url.Parse(srv.URL)
err := svc.SendNtfy(
context.Background(), topicURL, "t", "m", "info",
)
if err == nil {
t.Fatal("expected error for 500 response")
}
if !errors.Is(err, notify.ErrNtfyFailed) {
t.Errorf("error = %v, want ErrNtfyFailed", err)
}
} }
func TestSendNtfySuccess(t *testing.T) { func TestSendNtfySuccess(t *testing.T) {
@@ -633,19 +618,53 @@ func TestSendSlackAllColors(t *testing.T) {
func TestSendSlackClientError(t *testing.T) { func TestSendSlackClientError(t *testing.T) {
t.Parallel() t.Parallel()
assertSendStatusError( srv := httptest.NewServer(
t, http.StatusBadRequest, http.HandlerFunc(
notify.ErrSlackFailed, sendSlackInfo, func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusBadRequest)
}),
) )
defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport)
webhookURL, _ := url.Parse(srv.URL)
err := svc.SendSlack(
context.Background(), webhookURL, "t", "m", "info",
)
if err == nil {
t.Fatal("expected error for 400 response")
}
if !errors.Is(err, notify.ErrSlackFailed) {
t.Errorf("error = %v, want ErrSlackFailed", err)
}
} }
func TestSendSlackServerError(t *testing.T) { func TestSendSlackServerError(t *testing.T) {
t.Parallel() t.Parallel()
assertSendStatusError( srv := httptest.NewServer(
t, http.StatusBadGateway, http.HandlerFunc(
notify.ErrSlackFailed, sendSlackInfo, func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusBadGateway)
}),
) )
defer srv.Close()
svc := notify.NewTestService(srv.Client().Transport)
webhookURL, _ := url.Parse(srv.URL)
err := svc.SendSlack(
context.Background(), webhookURL, "t", "m", "error",
)
if err == nil {
t.Fatal("expected error for 502 response")
}
if !errors.Is(err, notify.ErrSlackFailed) {
t.Errorf("error = %v, want ErrSlackFailed", err)
}
} }
func TestSendSlackNetworkError(t *testing.T) { func TestSendSlackNetworkError(t *testing.T) {
@@ -970,62 +989,74 @@ func TestSendNotificationMattermostOnly(t *testing.T) {
} }
} }
// assertSendNotificationTolerates verifies SendNotification func TestSendNotificationNtfyError(t *testing.T) {
// neither panics nor blocks when the endpoint configured by t.Parallel()
// setURL responds with status.
func assertSendNotificationTolerates(
t *testing.T,
status int,
priority string,
setURL func(*notify.Service, *url.URL),
) {
t.Helper()
srv := httptest.NewServer( srv := httptest.NewServer(
http.HandlerFunc( http.HandlerFunc(
func(w http.ResponseWriter, _ *http.Request) { func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(status) w.WriteHeader(http.StatusInternalServerError)
}), }),
) )
defer srv.Close() defer srv.Close()
target, _ := url.Parse(srv.URL) ntfyURL, _ := url.Parse(srv.URL)
svc := notify.NewTestService(http.DefaultTransport) svc := notify.NewTestService(http.DefaultTransport)
setURL(svc, target) svc.SetNtfyURL(ntfyURL)
// Should not panic or block.
svc.SendNotification( svc.SendNotification(
context.Background(), "t", "m", priority, context.Background(), "t", "m", "error",
) )
time.Sleep(100 * time.Millisecond) time.Sleep(100 * time.Millisecond)
} }
func TestSendNotificationNtfyError(t *testing.T) {
t.Parallel()
assertSendNotificationTolerates(
t, http.StatusInternalServerError, prioError,
(*notify.Service).SetNtfyURL,
)
}
func TestSendNotificationSlackError(t *testing.T) { func TestSendNotificationSlackError(t *testing.T) {
t.Parallel() t.Parallel()
assertSendNotificationTolerates( srv := httptest.NewServer(
t, http.StatusForbidden, prioError, http.HandlerFunc(
(*notify.Service).SetSlackWebhookURL, func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusForbidden)
}),
) )
defer srv.Close()
slackURL, _ := url.Parse(srv.URL)
svc := notify.NewTestService(http.DefaultTransport)
svc.SetSlackWebhookURL(slackURL)
svc.SendNotification(
context.Background(), "t", "m", "error",
)
time.Sleep(100 * time.Millisecond)
} }
func TestSendNotificationMattermostError(t *testing.T) { func TestSendNotificationMattermostError(t *testing.T) {
t.Parallel() t.Parallel()
assertSendNotificationTolerates( srv := httptest.NewServer(
t, http.StatusBadGateway, prioWarning, http.HandlerFunc(
(*notify.Service).SetMattermostWebhookURL, func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusBadGateway)
}),
) )
defer srv.Close()
mmURL, _ := url.Parse(srv.URL)
svc := notify.NewTestService(http.DefaultTransport)
svc.SetMattermostWebhookURL(mmURL)
svc.SendNotification(
context.Background(), "t", "m", "warning",
)
time.Sleep(100 * time.Millisecond)
} }
// ── SlackPayload JSON marshaling ────────────────────────── // ── SlackPayload JSON marshaling ──────────────────────────

View File

@@ -69,7 +69,7 @@ func (rc RetryConfig) backoff(attempt int) time.Duration {
lo := raw * (1 - jitterFraction) lo := raw * (1 - jitterFraction)
hi := raw * (1 + jitterFraction) hi := raw * (1 + jitterFraction)
jittered := lo + rand.Float64()*(hi-lo) //nolint:gosec // jitter needs no crypto/rand jittered := lo + rand.Float64()*(hi-lo) //nolint:gosec // jitter does not need crypto/rand
return time.Duration(jittered) return time.Duration(jittered)
} }

View File

@@ -7,8 +7,8 @@ import (
"github.com/miekg/dns" "github.com/miekg/dns"
) )
// DNSClient abstracts DNS wire-protocol exchanges over a single // DNSClient abstracts DNS wire-protocol exchanges so the resolver
// transport, letting the resolver switch between UDP and TCP. // can be tested without hitting real nameservers.
type DNSClient interface { type DNSClient interface {
ExchangeContext( ExchangeContext(
ctx context.Context, ctx context.Context,

View File

@@ -67,4 +67,17 @@ func NewFromLogger(log *slog.Logger) *Resolver {
} }
} }
// NewFromLoggerWithClient creates a Resolver with a custom DNS
// client, useful for testing with mock DNS responses.
func NewFromLoggerWithClient(
log *slog.Logger,
client DNSClient,
) *Resolver {
return &Resolver{
log: log,
client: client,
tcp: client,
}
}
// Method implementations are in iterative.go. // Method implementations are in iterative.go.

View File

@@ -10,6 +10,7 @@ import (
"testing" "testing"
"time" "time"
"github.com/miekg/dns"
"github.com/stretchr/testify/assert" "github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require" "github.com/stretchr/testify/require"
@@ -623,41 +624,58 @@ func TestQueryAllNameservers_ContextCanceled(t *testing.T) {
} }
// ---------------------------------------------------------------- // ----------------------------------------------------------------
// Unreachable nameserver tests // Timeout tests
// ---------------------------------------------------------------- // ----------------------------------------------------------------
func TestQueryNameserverIP_UnreachableServer(t *testing.T) { func TestQueryNameserverIP_Timeout(t *testing.T) {
t.Parallel() t.Parallel()
r := newTestResolver(t) log := slog.New(slog.NewTextHandler(
os.Stderr,
&slog.HandlerOptions{Level: slog.LevelDebug},
))
r := resolver.NewFromLoggerWithClient(
log, &timeoutClient{},
)
ctx, cancel := context.WithTimeout( ctx, cancel := context.WithTimeout(
context.Background(), 10*time.Second, context.Background(), 10*time.Second,
) )
t.Cleanup(cancel) t.Cleanup(cancel)
// 192.0.2.1 is an RFC 5737 documentation address: no // Query any IP — the client always returns a timeout error.
// nameserver can exist there. Depending on the network
// path the queries either time out (silent drop) or fail
// fast (ICMP unreachable), so accept any non-OK status;
// the resolver must return a classified response with no
// records rather than an error or a hang.
resp, err := r.QueryNameserverIP( resp, err := r.QueryNameserverIP(
ctx, "unreachable.test.", "192.0.2.1", ctx, "unreachable.test.", "192.0.2.1",
"example.com", "example.com",
) )
require.NoError(t, err) require.NoError(t, err)
assert.NotEqual(t, resolver.StatusOK, resp.Status) assert.Equal(t, resolver.StatusTimeout, resp.Status)
assert.NotEmpty(t, resp.Error)
totalRecords := 0
for _, values := range resp.Records {
totalRecords += len(values)
}
assert.Zero(t, totalRecords)
} }
// timeoutClient simulates DNS timeout errors for testing.
type timeoutClient struct{}
func (c *timeoutClient) ExchangeContext(
_ context.Context,
_ *dns.Msg,
_ string,
) (*dns.Msg, time.Duration, error) {
return nil, 0, &net.OpError{
Op: "read",
Net: "udp",
Err: &timeoutError{},
}
}
type timeoutError struct{}
func (e *timeoutError) Error() string { return "i/o timeout" }
func (e *timeoutError) Timeout() bool { return true }
func (e *timeoutError) Temporary() bool { return true }
func TestResolveIPAddresses_ContextCanceled(t *testing.T) { func TestResolveIPAddresses_ContextCanceled(t *testing.T) {
t.Parallel() t.Parallel()

View File

@@ -223,8 +223,7 @@ func TestSaveLoadRoundTrip_Ports(t *testing.T) {
} }
} }
// TestSaveLoadRoundTrip_Certificates verifies certificate data // TestSaveLoadRoundTrip_Certificates verifies certificate data survives a save/load cycle.
// survives a save/load cycle.
func TestSaveLoadRoundTrip_Certificates(t *testing.T) { func TestSaveLoadRoundTrip_Certificates(t *testing.T) {
t.Parallel() t.Parallel()
@@ -1073,8 +1072,7 @@ func TestConcurrentGetSet(t *testing.T) {
wg.Wait() wg.Wait()
} }
// runConcurrentOps performs a series of get/set/delete // runConcurrentOps performs a series of get/set/delete operations for concurrency testing.
// operations for concurrency testing.
func runConcurrentOps(s *state.State, key string, now time.Time) { func runConcurrentOps(s *state.State, key string, now time.Time) {
const iterations = 50 const iterations = 50

View File

@@ -26,11 +26,8 @@ const tlsPort = 443
// hoursPerDay converts days to hours for duration calculations. // hoursPerDay converts days to hours for duration calculations.
const hoursPerDay = 24 const hoursPerDay = 24
// Status values recorded for nameserver and certificate checks. // statusError is the status value recorded for failed checks.
const ( const statusError = "error"
statusOK = "ok"
statusError = "error"
)
// Params contains dependencies for Watcher. // Params contains dependencies for Watcher.
type Params struct { type Params struct {
@@ -350,7 +347,7 @@ func buildHostnameState(
for ns, recs := range records { for ns, recs := range records {
hs.RecordsByNameserver[ns] = &state.NameserverRecordState{ hs.RecordsByNameserver[ns] = &state.NameserverRecordState{
Records: recs, Records: recs,
Status: statusOK, Status: "ok",
LastChecked: now, LastChecked: now,
} }
} }
@@ -408,7 +405,7 @@ func (w *Watcher) detectNSDisappearances(
current map[string]map[string][]string, current map[string]map[string][]string,
) { ) {
for ns, prevNS := range prev.RecordsByNameserver { for ns, prevNS := range prev.RecordsByNameserver {
if _, ok := current[ns]; ok || prevNS.Status != statusOK { if _, ok := current[ns]; ok || prevNS.Status != "ok" {
continue continue
} }
@@ -711,7 +708,7 @@ func (w *Watcher) handleTLSError(
now time.Time, now time.Time,
err error, err error,
) { ) {
if hasPrev && !w.firstRun && prev.Status == statusOK { if hasPrev && !w.firstRun && prev.Status == "ok" {
msg := fmt.Sprintf( msg := fmt.Sprintf(
"Host: %s\nIP: %s\nError: %s", "Host: %s\nIP: %s\nError: %s",
hostname, ip, err, hostname, ip, err,
@@ -754,7 +751,7 @@ func (w *Watcher) handleTLSSuccess(
Issuer: cert.Issuer, Issuer: cert.Issuer,
NotAfter: cert.NotAfter, NotAfter: cert.NotAfter,
SubjectAlternativeNames: cert.SubjectAlternativeNames, SubjectAlternativeNames: cert.SubjectAlternativeNames,
Status: statusOK, Status: "ok",
LastChecked: now, LastChecked: now,
}, },
) )

File diff suppressed because it is too large Load Diff