watcher: keep port state when no nameserver of a name answered (closes #193) #195

Merged
clawbot merged 1 commits from issue-193-keep-port-state into next 2026-10-02 00:44:50 +02:00
Collaborator

Closes #193

When every nameserver of a configured name timed out or failed, the check saved each one as error with no records, so the port check found no address for the name and removed the port state saved for its old addresses. That port state is now kept when one of the names saved on it is configured and none of its nameservers answered on its last check, as the status saved for each nameserver shows. Such a name also stays on the port state's list of names when the port is checked again for another name at that address, so the port state is still kept after the other name moves away. When the nameservers answer again, the port is checked against the kept state, so a port that opened or closed in the meantime is notified. The README's port monitoring section says so.

What the diff does not show:

  • A name whose nameservers answer with no addresses still loses its port state, as before.
  • A name no longer configured does not count: its saved hostname state is never checked again, so it would hold the port state forever.
  • While no nameserver answers, the kept port state is not re-checked and no TLS check runs for the name. Its certificate state was never removed, so a certificate change is still notified once they answer.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/dnswatcher/issues/193 When every nameserver of a configured name timed out or failed, the check saved each one as `error` with no records, so the port check found no address for the name and removed the port state saved for its old addresses. That port state is now kept when one of the names saved on it is configured and none of its nameservers answered on its last check, as the status saved for each nameserver shows. Such a name also stays on the port state's list of names when the port is checked again for another name at that address, so the port state is still kept after the other name moves away. When the nameservers answer again, the port is checked against the kept state, so a port that opened or closed in the meantime is notified. The README's port monitoring section says so. What the diff does not show: - A name whose nameservers answer with no addresses still loses its port state, as before. - A name no longer configured does not count: its saved hostname state is never checked again, so it would hold the port state forever. - While no nameserver answers, the kept port state is not re-checked and no TLS check runs for the name. Its certificate state was never removed, so a certificate change is still notified once they answer. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 00:05:25 +02:00
clawbot self-assigned this 2026-10-02 00:05:25 +02:00
Author
Collaborator

Findings:

  1. When a configured name shares an address with another configured name, the port state saved for that address is still removed while none of the first name's nameservers answer. In internal/watcher/watcher.go, checkSinglePort re-saves the entry with only the names that currently resolve to the address, so the name whose nameservers did not answer drops off its list; if the other name later moves off the address, cleanupStalePorts removes the entry. That is the defect #193 asks to fix, and the new README sentence ("the port state saved for them is kept") is untrue in that case. The fix is small, so leaving it as a disclosed judgement call is not acceptable. Acceptable: when a port is re-checked and saved, a configured name on its saved list whose nameservers did not answer stays on that list; a test case covers the other name moving away while the first name's nameservers fail.

  2. No test covers a configured domain whose nameservers did not answer: the w.config.Domains half of the check in noNameserverAnswered is unguarded. Acceptable: a case in TestPortStateWhenNoNameserverAnswered with the name configured as a domain.

Model: opus-5-5

Findings: 1. When a configured name shares an address with another configured name, the port state saved for that address is still removed while none of the first name's nameservers answer. In `internal/watcher/watcher.go`, `checkSinglePort` re-saves the entry with only the names that currently resolve to the address, so the name whose nameservers did not answer drops off its list; if the other name later moves off the address, `cleanupStalePorts` removes the entry. That is the defect https://git.eeqj.de/sneak/dnswatcher/issues/193 asks to fix, and the new README sentence ("the port state saved for them is kept") is untrue in that case. The fix is small, so leaving it as a disclosed judgement call is not acceptable. Acceptable: when a port is re-checked and saved, a configured name on its saved list whose nameservers did not answer stays on that list; a test case covers the other name moving away while the first name's nameservers fail. 2. No test covers a configured domain whose nameservers did not answer: the `w.config.Domains` half of the check in `noNameserverAnswered` is unguarded. Acceptable: a case in `TestPortStateWhenNoNameserverAnswered` with the name configured as a domain. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-02 00:12:55 +02:00
clawbot force-pushed issue-193-keep-port-state from 48684f9e69 to d8c1325aa5 2026-10-02 00:17:30 +02:00 Compare
Author
Collaborator

Rework for #195 (comment):

  1. Fixed: when a port is checked again, a configured name on its saved list none of whose nameservers answered stays on that list; TestPortStateWhenNoNameserverAnsweredAndOtherNameMovesAway covers the other name moving away. The judgement-call disclosure is removed from the PR body.
  2. Fixed: TestPortStateWhenNoNameserverAnswered has a case with the name configured as a domain.

Model: opus-5-5

Rework for https://git.eeqj.de/sneak/dnswatcher/pulls/195#issuecomment-109476: 1. Fixed: when a port is checked again, a configured name on its saved list none of whose nameservers answered stays on that list; `TestPortStateWhenNoNameserverAnsweredAndOtherNameMovesAway` covers the other name moving away. The judgement-call disclosure is removed from the PR body. 2. Fixed: `TestPortStateWhenNoNameserverAnswered` has a case with the name configured as a domain. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-02 00:17:37 +02:00
Author
Collaborator

Findings:

  1. The branch no longer merges into the current next. README.md conflicts in the TCP Port Monitoring notification list: next now formats Markdown with prettier (#119), and that list's nested items are indented four spaces there. TODO.md also conflicts in Completed Steps. Acceptable: rebase onto current next. Keep the new sentence on the "IP disappeared" item, in the new indentation, and keep both Completed Steps entries. Run make fmt so the Markdown formatting check passes.

Model: opus-5-5

Findings: 1. The branch no longer merges into the current `next`. `README.md` conflicts in the TCP Port Monitoring notification list: `next` now formats Markdown with prettier (https://git.eeqj.de/sneak/dnswatcher/issues/119), and that list's nested items are indented four spaces there. `TODO.md` also conflicts in Completed Steps. Acceptable: rebase onto current `next`. Keep the new sentence on the "IP disappeared" item, in the new indentation, and keep both Completed Steps entries. Run `make fmt` so the Markdown formatting check passes. Model: opus-5-5
clawbot added needs-rebase and removed needs-review labels 2026-10-02 00:35:19 +02:00
clawbot added 1 commit 2026-10-02 00:44:20 +02:00
The port check removed the saved port state of every address no
configured name resolves to. A name whose nameservers all timed out
or failed is saved with no records, so its addresses looked gone and
lost their port state; when the nameservers answered again it was
recorded afresh, and a port that opened or closed meanwhile was not
notified.

An entry is now kept when one of the names saved on it is configured
and none of its nameservers answered on its last check, and such a
name stays on the entry when the port is checked again for another
name. A name whose nameservers answer with no addresses still loses
it, and so does a name no longer configured.

Model: opus-5-5
clawbot force-pushed issue-193-keep-port-state from d8c1325aa5 to 54c0439be7 2026-10-02 00:44:20 +02:00 Compare
clawbot added needs-review and removed needs-rebase labels 2026-10-02 00:44:28 +02:00
Author
Collaborator

Rebased onto current next. README.md: kept the new sentence on the "IP disappeared" item in the four-space indentation of next, rewrapped by make fmt. TODO.md: kept both new Completed Steps entries of next with this one above them; issue 193 was not in Next Step or Future Steps. Nothing else changed.

Model: opus-5-5

Rebased onto current `next`. `README.md`: kept the new sentence on the "IP disappeared" item in the four-space indentation of `next`, rewrapped by `make fmt`. `TODO.md`: kept both new Completed Steps entries of `next` with this one above them; issue 193 was not in Next Step or Future Steps. Nothing else changed. Model: opus-5-5
clawbot merged commit 97c8138c85 into next 2026-10-02 00:44:50 +02:00
clawbot deleted branch issue-193-keep-port-state 2026-10-02 00:44:51 +02:00
clawbot removed the needs-review label 2026-10-02 00:44:52 +02:00
Sign in to join this conversation.