The README says a certificate inside the warning window gets a warning "repeated each check until renewed or expired". checkTLSExpiry in internal/watcher/watcher.go sends none for a hostname and address that got one less than DNSWATCHER_TLS_INTERVAL ago. TLS checks start once per interval, but each runs after a DNS pass of varying length, so two checks' warnings are the interval apart plus the difference between those DNS passes. When the later pass is the shorter, the gap is under the interval and the warning is skipped: a certificate about to expire is warned about on every check or every other check, at random.
#18 asked for fewer repeats; the README promises one per check. Which is wanted is the owner's call.
Definition of done
Expiry warnings follow one rule, stated in the README, that does not depend on how long a DNS pass took.
A test shows it on certificate data built in the test, with no DNS involved.
Model: opus-5-5
Found while checking the README for https://git.eeqj.de/sneak/dnswatcher/issues/108.
The README says a certificate inside the warning window gets a warning "repeated each check until renewed or expired". `checkTLSExpiry` in `internal/watcher/watcher.go` sends none for a hostname and address that got one less than `DNSWATCHER_TLS_INTERVAL` ago. TLS checks start once per interval, but each runs after a DNS pass of varying length, so two checks' warnings are the interval apart plus the difference between those DNS passes. When the later pass is the shorter, the gap is under the interval and the warning is skipped: a certificate about to expire is warned about on every check or every other check, at random.
https://git.eeqj.de/sneak/dnswatcher/issues/18 asked for fewer repeats; the README promises one per check. Which is wanted is the owner's call.
## Definition of done
- Expiry warnings follow one rule, stated in the README, that does not depend on how long a DNS pass took.
- A test shows it on certificate data built in the test, with no DNS involved.
Model: opus-5-5
Plan; this needs no decision from sneak. TLS checks start once per DNSWATCHER_TLS_INTERVAL, so "one warning per check", as the README says, is also the "no more than once per interval" that #18 asked for. The rule: each TLS check sends at most one expiry warning per hostname and address while the certificate is in the warning window, and the decision does not compare wall-clock times against the interval. The README keeps its wording; the test runs successive checks on certificate data built in the test, with gaps shorter and longer than the interval, and expects one warning per check.
Model: opus-5-5
Plan; this needs no decision from sneak. TLS checks start once per `DNSWATCHER_TLS_INTERVAL`, so "one warning per check", as the README says, is also the "no more than once per interval" that https://git.eeqj.de/sneak/dnswatcher/issues/18 asked for. The rule: each TLS check sends at most one expiry warning per hostname and address while the certificate is in the warning window, and the decision does not compare wall-clock times against the interval. The README keeps its wording; the test runs successive checks on certificate data built in the test, with gaps shorter and longer than the interval, and expects one warning per check.
Model: opus-5-5
Built in #208: every TLS check warns once per hostname and address while the certificate is within the warning period, with no comparison against the TLS interval. A target listed twice now gets two warnings per check: #207.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/dnswatcher/pulls/208: every TLS check warns once per hostname and address while the certificate is within the warning period, with no comparison against the TLS interval. A target listed twice now gets two warnings per check: https://git.eeqj.de/sneak/dnswatcher/issues/207.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while checking the README for #108.
The README says a certificate inside the warning window gets a warning "repeated each check until renewed or expired".
checkTLSExpiryininternal/watcher/watcher.gosends none for a hostname and address that got one less thanDNSWATCHER_TLS_INTERVALago. TLS checks start once per interval, but each runs after a DNS pass of varying length, so two checks' warnings are the interval apart plus the difference between those DNS passes. When the later pass is the shorter, the gap is under the interval and the warning is skipped: a certificate about to expire is warned about on every check or every other check, at random.#18 asked for fewer repeats; the README promises one per check. Which is wanted is the owner's call.
Definition of done
Model: opus-5-5
clawbot referenced this issue2026-10-02 01:36:55 +02:00
Plan; this needs no decision from sneak. TLS checks start once per
DNSWATCHER_TLS_INTERVAL, so "one warning per check", as the README says, is also the "no more than once per interval" that #18 asked for. The rule: each TLS check sends at most one expiry warning per hostname and address while the certificate is in the warning window, and the decision does not compare wall-clock times against the interval. The README keeps its wording; the test runs successive checks on certificate data built in the test, with gaps shorter and longer than the interval, and expects one warning per check.Model: opus-5-5
Built in #208: every TLS check warns once per hostname and address while the certificate is within the warning period, with no comparison against the TLS interval. A target listed twice now gets two warnings per check: #207.
Model: opus-5-5