The README said each watched name's addresses for the port and TLS checks come "via A, AAAA, and CNAME chain resolution". The code does not follow a CNAME there: collectIPs in internal/watcher/watcher.go takes only the A and AAAA records in the answers that LookupAllRecords saved, and LookupAllRecords stores a CNAME without following it. A name whose CNAME points into another zone (say www.example.com CNAME site.cdn.example.net.) usually gets no addresses, so its ports 80 and 443 and its certificate are never checked, and nothing reports that. ResolveIPAddresses does follow CNAMEs, but only nameserver addresses use it.
The PR for #108 changes the README to say what the code does now.
Definition of done
The port and TLS checks for a watched name use the addresses at the end of its CNAME chain.
Tested against live DNS, or on record data built in the test; no stand-in resolver.
README "TCP Port Monitoring" and "DNS Resolution Strategy" say so.
Model: opus-5-5
Found while checking the README for https://git.eeqj.de/sneak/dnswatcher/issues/108.
The README said each watched name's addresses for the port and TLS checks come "via A, AAAA, and CNAME chain resolution". The code does not follow a CNAME there: `collectIPs` in `internal/watcher/watcher.go` takes only the A and AAAA records in the answers that `LookupAllRecords` saved, and `LookupAllRecords` stores a CNAME without following it. A name whose CNAME points into another zone (say `www.example.com` CNAME `site.cdn.example.net.`) usually gets no addresses, so its ports 80 and 443 and its certificate are never checked, and nothing reports that. `ResolveIPAddresses` does follow CNAMEs, but only nameserver addresses use it.
The PR for https://git.eeqj.de/sneak/dnswatcher/issues/108 changes the README to say what the code does now.
## Definition of done
- The port and TLS checks for a watched name use the addresses at the end of its CNAME chain.
- Tested against live DNS, or on record data built in the test; no stand-in resolver.
- README "TCP Port Monitoring" and "DNS Resolution Strategy" say so.
Model: opus-5-5
Implemented in #209: when a watched name's nameservers answer with a CNAME and no address, the DNS check follows it with ResolveIPAddresses, and the port and TLS checks use the addresses at the end of the chain.
Model: opus-5-5
Implemented in https://git.eeqj.de/sneak/dnswatcher/pulls/209: when a watched name's nameservers answer with a CNAME and no address, the DNS check follows it with `ResolveIPAddresses`, and the port and TLS checks use the addresses at the end of the chain.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while checking the README for #108.
The README said each watched name's addresses for the port and TLS checks come "via A, AAAA, and CNAME chain resolution". The code does not follow a CNAME there:
collectIPsininternal/watcher/watcher.gotakes only the A and AAAA records in the answers thatLookupAllRecordssaved, andLookupAllRecordsstores a CNAME without following it. A name whose CNAME points into another zone (saywww.example.comCNAMEsite.cdn.example.net.) usually gets no addresses, so its ports 80 and 443 and its certificate are never checked, and nothing reports that.ResolveIPAddressesdoes follow CNAMEs, but only nameserver addresses use it.The PR for #108 changes the README to say what the code does now.
Definition of done
Model: opus-5-5
Implemented in #209: when a watched name's nameservers answer with a CNAME and no address, the DNS check follows it with
ResolveIPAddresses, and the port and TLS checks use the addresses at the end of the chain.Model: opus-5-5