Saved port state is removed when every nameserver of a hostname fails #193

Closed
opened 2026-10-01 23:44:13 +02:00 by clawbot · 1 comment
Collaborator

Found while working on #190.

The port and TLS checks do not call ResolveIPAddresses; they take a hostname's addresses from the records saved for it. When every nameserver of the hostname times out or fails, each one is saved as error with empty records, so for that check the hostname has no addresses. The port check then removes the saved port state of the hostname's addresses (unless another target still resolves to them), and no TLS check runs for the hostname. When the nameservers answer again, the port state is recorded afresh, so a port that opened or closed in the meantime is not notified.

Definition of done

  • When no nameserver of a hostname answered, its saved port state is kept, not removed; a hostname whose nameservers answer with no addresses still has its port state removed as today.
  • A test covers both cases, with hostname state built in the test (no lookup) or live DNS. No stand-in resolver.

Model: opus-5-5

Found while working on https://git.eeqj.de/sneak/dnswatcher/issues/190. The port and TLS checks do not call `ResolveIPAddresses`; they take a hostname's addresses from the records saved for it. When every nameserver of the hostname times out or fails, each one is saved as `error` with empty `records`, so for that check the hostname has no addresses. The port check then removes the saved port state of the hostname's addresses (unless another target still resolves to them), and no TLS check runs for the hostname. When the nameservers answer again, the port state is recorded afresh, so a port that opened or closed in the meantime is not notified. ## Definition of done - When no nameserver of a hostname answered, its saved port state is kept, not removed; a hostname whose nameservers answer with no addresses still has its port state removed as today. - A test covers both cases, with hostname state built in the test (no lookup) or live DNS. No stand-in resolver. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-01 23:51:23 +02:00
Author
Collaborator

Fixed in #195: when none of a configured name's nameservers answered, the port state saved for its addresses is kept; a name whose nameservers answer with no addresses still loses it.

Model: opus-5-5

Fixed in https://git.eeqj.de/sneak/dnswatcher/pulls/195: when none of a configured name's nameservers answered, the port state saved for its addresses is kept; a name whose nameservers answer with no addresses still loses it. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#193