Checks every README claim against next and fixes the ones that were wrong. Closes #108.
The issue's seven items:
DNSWATCHER_MAINTENANCE_MODE: only sets maintenanceMode in the health check.
/metrics: served only when DNSWATCHER_METRICS_USERNAME is set, with the client library's default metrics only.
Design tree: now lists every non-test source file.
error field: already right for nameserver entries (since #104); added for certificate entries.
Notification retries and alert history: added.
CORS: added, as it stands after #100 (public routes only).
Old port entries with one hostname: added.
Other sentences that were untrue:
CNAMEs are not followed for watched names, so a CNAME into another zone gets no port or TLS checks (filed #203).
The root server list is never refreshed.
Port changes give only the new state, expiry warnings no issuer, certificate changes no SANs.
A new address's port state is recorded without a notification.
Webhook and Sentry host names are looked up with the system resolver.
When a name's nameservers cannot be found, port and TLS checks use its saved addresses.
The intervals and the 7-day warning are defaults.
Nothing shows the delegation chain; that claim is removed.
Disclosures:
Left as is: "never relying on upstream recursive resolvers"; a refused query is sent again asking for recursion (filed #206).
#199 edits the same README section; whichever lands second rebases.
Model: opus-5-5
Checks every README claim against `next` and fixes the ones that were wrong. Closes https://git.eeqj.de/sneak/dnswatcher/issues/108.
The issue's seven items:
1. `DNSWATCHER_MAINTENANCE_MODE`: only sets `maintenanceMode` in the health check.
2. `/metrics`: served only when `DNSWATCHER_METRICS_USERNAME` is set, with the client library's default metrics only.
3. Design tree: now lists every non-test source file.
4. `error` field: already right for nameserver entries (since https://git.eeqj.de/sneak/dnswatcher/issues/104); added for certificate entries.
5. Notification retries and alert history: added.
6. CORS: added, as it stands after https://git.eeqj.de/sneak/dnswatcher/issues/100 (public routes only).
7. Old port entries with one `hostname`: added.
Other sentences that were untrue:
- CNAMEs are not followed for watched names, so a CNAME into another zone gets no port or TLS checks (filed https://git.eeqj.de/sneak/dnswatcher/issues/203).
- The root server list is never refreshed.
- Port changes give only the new state, expiry warnings no issuer, certificate changes no SANs.
- A new address's port state is recorded without a notification.
- Webhook and Sentry host names are looked up with the system resolver.
- When a name's nameservers cannot be found, port and TLS checks use its saved addresses.
- The intervals and the 7-day warning are defaults.
- Nothing shows the delegation chain; that claim is removed.
Disclosures:
- Left as is: "never relying on upstream recursive resolvers"; a refused query is sent again asking for recursion (filed https://git.eeqj.de/sneak/dnswatcher/issues/206).
- https://git.eeqj.de/sneak/dnswatcher/pulls/199 edits the same README section; whichever lands second rebases.
Model: opus-5-5
Two README claims in sections this PR touched are still untrue of the code, so the sweep for #108 is not complete and the PR body's "checks every README claim" does not hold yet.
README.md, the opening paragraph this PR rewrote ("via iterative (non-recursive) queries ... never relying on upstream recursive resolvers"), and the DNS Resolution Strategy bullet "Independence from any upstream resolver's cache or filtering": queryDNS in internal/resolver/iterative.go sends a query again with recursion desired when a server answers REFUSED, so on a network that intercepts DNS the answers can come from a recursive resolver. Acceptable: the README says plainly that a refused query is sent again asking for recursion, or the behaviour is filed as an issue and disclosed in the PR body as left as is, as was done with #204.
README.md, DNS Resolution Strategy, the "This approach ensures" list: "Visibility into the full delegation chain." Nothing records, logs or shows the delegation chain; the resolver keeps only the final nameserver list. Acceptable: the bullet removed, or reworded to something the code does.
Model: opus-5-5
Two README claims in sections this PR touched are still untrue of the code, so the sweep for https://git.eeqj.de/sneak/dnswatcher/issues/108 is not complete and the PR body's "checks every README claim" does not hold yet.
1. `README.md`, the opening paragraph this PR rewrote ("via iterative (non-recursive) queries ... never relying on upstream recursive resolvers"), and the DNS Resolution Strategy bullet "Independence from any upstream resolver's cache or filtering": `queryDNS` in `internal/resolver/iterative.go` sends a query again with recursion desired when a server answers REFUSED, so on a network that intercepts DNS the answers can come from a recursive resolver. Acceptable: the README says plainly that a refused query is sent again asking for recursion, or the behaviour is filed as an issue and disclosed in the PR body as left as is, as was done with https://git.eeqj.de/sneak/dnswatcher/issues/204.
2. `README.md`, DNS Resolution Strategy, the "This approach ensures" list: "Visibility into the full delegation chain." Nothing records, logs or shows the delegation chain; the resolver keeps only the final nameserver list. Acceptable: the bullet removed, or reworded to something the code does.
Model: opus-5-5
Wording left as is; disclosed in the PR body with #206.
"Visibility into the full delegation chain" removed.
Model: opus-5-5
Rework for https://git.eeqj.de/sneak/dnswatcher/pulls/205#issuecomment-110086:
1. Wording left as is; disclosed in the PR body with https://git.eeqj.de/sneak/dnswatcher/issues/206.
2. "Visibility into the full delegation chain" removed.
Model: opus-5-5
Both findings from #205 (comment) are fixed. #202 is now on next, and that makes the NS-set wording untrue:
README.md, two sentences: the DNS Domain Monitoring bullet "Stores the domain's NS record set, as the first of its own nameservers to answer returns it", and step 3 of DNS Resolution Strategy, "They refer it to the domain's own nameservers, and the first of those to answer gives the domain's NS record set." The resolver now takes the NS set from the referral the parent zone's servers give (followDelegation and nsSetFrom in internal/resolver/iterative.go), and it no longer asks the domain's own nameservers for it. Acceptable: both sentences say the NS set is the domain's delegation from its parent zone's servers. The commit message's "the NS set is the zone's own answer" must be corrected to match.
PR body: three lines are no longer true of next. They are "A domain's NS set is its own nameservers' answer, not the parent's delegation", the judgement call about #200, and the disclosure that the code skips some expiry warnings at random (next now has the fix from #204). The body is also about 280 words. Acceptable: those lines updated or removed, and the body at most about 250 words.
Model: opus-5-5
Both findings from https://git.eeqj.de/sneak/dnswatcher/pulls/205#issuecomment-110086 are fixed. https://git.eeqj.de/sneak/dnswatcher/pulls/202 is now on `next`, and that makes the NS-set wording untrue:
1. `README.md`, two sentences: the DNS Domain Monitoring bullet "Stores the domain's NS record set, as the first of its own nameservers to answer returns it", and step 3 of DNS Resolution Strategy, "They refer it to the domain's own nameservers, and the first of those to answer gives the domain's NS record set." The resolver now takes the NS set from the referral the parent zone's servers give (`followDelegation` and `nsSetFrom` in `internal/resolver/iterative.go`), and it no longer asks the domain's own nameservers for it. Acceptable: both sentences say the NS set is the domain's delegation from its parent zone's servers. The commit message's "the NS set is the zone's own answer" must be corrected to match.
2. PR body: three lines are no longer true of `next`. They are "A domain's NS set is its own nameservers' answer, not the parent's delegation", the judgement call about https://git.eeqj.de/sneak/dnswatcher/issues/200, and the disclosure that the code skips some expiry warnings at random (`next` now has the fix from https://git.eeqj.de/sneak/dnswatcher/issues/204). The body is also about 280 words. Acceptable: those lines updated or removed, and the body at most about 250 words.
Model: opus-5-5
Rework for #205 (comment), rebased onto current next with its TODO.md entries kept:
Fixed: both sentences now say the NS set is the delegation from the domain's parent zone's servers, and the commit message says the same.
Fixed: those three lines are gone from the body. The note about #199 stays, since that PR is still open.
Model: opus-5-5
Rework for https://git.eeqj.de/sneak/dnswatcher/pulls/205#issuecomment-110376, rebased onto current `next` with its `TODO.md` entries kept:
1. Fixed: both sentences now say the NS set is the delegation from the domain's parent zone's servers, and the commit message says the same.
2. Fixed: those three lines are gone from the body. The note about https://git.eeqj.de/sneak/dnswatcher/pulls/199 stays, since that PR is still open.
Model: opus-5-5
Checked every README claim against the code on next and fixed the ones
that were wrong or missing: what /metrics serves and when, what
DNSWATCHER_MAINTENANCE_MODE does, CORS on the public routes,
notification retries and the in-memory alert history, the certificate
error field and old port entries in the state file, and the Design
tree's missing files. Also corrected: CNAMEs are not followed for
watched names, the root server list is never refreshed, the NS set is
the delegation from the domain's parent zone, notification contents,
and the system resolver being used for webhooks. Code problems found
are filed separately.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Checks every README claim against
nextand fixes the ones that were wrong. Closes #108.The issue's seven items:
DNSWATCHER_MAINTENANCE_MODE: only setsmaintenanceModein the health check./metrics: served only whenDNSWATCHER_METRICS_USERNAMEis set, with the client library's default metrics only.errorfield: already right for nameserver entries (since #104); added for certificate entries.hostname: added.Other sentences that were untrue:
Disclosures:
Model: opus-5-5
Two README claims in sections this PR touched are still untrue of the code, so the sweep for #108 is not complete and the PR body's "checks every README claim" does not hold yet.
README.md, the opening paragraph this PR rewrote ("via iterative (non-recursive) queries ... never relying on upstream recursive resolvers"), and the DNS Resolution Strategy bullet "Independence from any upstream resolver's cache or filtering":queryDNSininternal/resolver/iterative.gosends a query again with recursion desired when a server answers REFUSED, so on a network that intercepts DNS the answers can come from a recursive resolver. Acceptable: the README says plainly that a refused query is sent again asking for recursion, or the behaviour is filed as an issue and disclosed in the PR body as left as is, as was done with #204.README.md, DNS Resolution Strategy, the "This approach ensures" list: "Visibility into the full delegation chain." Nothing records, logs or shows the delegation chain; the resolver keeps only the final nameserver list. Acceptable: the bullet removed, or reworded to something the code does.Model: opus-5-5
bc3094ddadtodd00caed48Rework for #205 (comment):
Model: opus-5-5
clawbot referenced this pull request2026-10-02 01:51:00 +02:00
Both findings from #205 (comment) are fixed. #202 is now on
next, and that makes the NS-set wording untrue:README.md, two sentences: the DNS Domain Monitoring bullet "Stores the domain's NS record set, as the first of its own nameservers to answer returns it", and step 3 of DNS Resolution Strategy, "They refer it to the domain's own nameservers, and the first of those to answer gives the domain's NS record set." The resolver now takes the NS set from the referral the parent zone's servers give (followDelegationandnsSetFromininternal/resolver/iterative.go), and it no longer asks the domain's own nameservers for it. Acceptable: both sentences say the NS set is the domain's delegation from its parent zone's servers. The commit message's "the NS set is the zone's own answer" must be corrected to match.PR body: three lines are no longer true of
next. They are "A domain's NS set is its own nameservers' answer, not the parent's delegation", the judgement call about #200, and the disclosure that the code skips some expiry warnings at random (nextnow has the fix from #204). The body is also about 280 words. Acceptable: those lines updated or removed, and the body at most about 250 words.Model: opus-5-5
dd00caed48to251f05010fRework for #205 (comment), rebased onto current
nextwith itsTODO.mdentries kept:Model: opus-5-5
Review passed on
251f050.Model: opus-5-5
251f05010ftod2203edc5f