A watched name whose CNAME points into another zone gets no port or TLS checks #203

Closed
opened 2026-10-02 01:34:46 +02:00 by clawbot · 1 comment
Collaborator

Found while checking the README for #108.

The README said each watched name's addresses for the port and TLS checks come "via A, AAAA, and CNAME chain resolution". The code does not follow a CNAME there: collectIPs in internal/watcher/watcher.go takes only the A and AAAA records in the answers that LookupAllRecords saved, and LookupAllRecords stores a CNAME without following it. A name whose CNAME points into another zone (say www.example.com CNAME site.cdn.example.net.) usually gets no addresses, so its ports 80 and 443 and its certificate are never checked, and nothing reports that. ResolveIPAddresses does follow CNAMEs, but only nameserver addresses use it.

The PR for #108 changes the README to say what the code does now.

Definition of done

  • The port and TLS checks for a watched name use the addresses at the end of its CNAME chain.
  • Tested against live DNS, or on record data built in the test; no stand-in resolver.
  • README "TCP Port Monitoring" and "DNS Resolution Strategy" say so.

Model: opus-5-5

Found while checking the README for https://git.eeqj.de/sneak/dnswatcher/issues/108. The README said each watched name's addresses for the port and TLS checks come "via A, AAAA, and CNAME chain resolution". The code does not follow a CNAME there: `collectIPs` in `internal/watcher/watcher.go` takes only the A and AAAA records in the answers that `LookupAllRecords` saved, and `LookupAllRecords` stores a CNAME without following it. A name whose CNAME points into another zone (say `www.example.com` CNAME `site.cdn.example.net.`) usually gets no addresses, so its ports 80 and 443 and its certificate are never checked, and nothing reports that. `ResolveIPAddresses` does follow CNAMEs, but only nameserver addresses use it. The PR for https://git.eeqj.de/sneak/dnswatcher/issues/108 changes the README to say what the code does now. ## Definition of done - The port and TLS checks for a watched name use the addresses at the end of its CNAME chain. - Tested against live DNS, or on record data built in the test; no stand-in resolver. - README "TCP Port Monitoring" and "DNS Resolution Strategy" say so. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 01:37:55 +02:00
Author
Collaborator

Implemented in #209: when a watched name's nameservers answer with a CNAME and no address, the DNS check follows it with ResolveIPAddresses, and the port and TLS checks use the addresses at the end of the chain.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/dnswatcher/pulls/209: when a watched name's nameservers answer with a CNAME and no address, the DNS check follows it with `ResolveIPAddresses`, and the port and TLS checks use the addresses at the end of the chain. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#203