watcher: warn of an expiring certificate on every TLS check (closes #204) #208

Merged
clawbot merged 1 commits from issue-204-expiry-warning-rule into next 2026-10-02 01:58:28 +02:00
Collaborator

Closes #204, following the plan in #204 (comment).

An expiry warning was skipped when the last one for the same hostname and address had been sent less than DNSWATCHER_TLS_INTERVAL ago. Each TLS check runs after a DNS pass of varying length, so two checks can be less than the interval apart, and a certificate about to expire was warned about on every check or every other check, at random. That record of when each warning was sent is removed: every TLS check now warns once per hostname and address while the certificate is within the warning period, which is what the README already says ("repeated each check until renewed or expired"), so the README is unchanged.

TLS checks start once per DNSWATCHER_TLS_INTERVAL, so this is still about one warning per interval. The removed record was held only in memory, so nothing in the state file changes.

The new test runs the TLS checks three times on hostname and port state built in the test, with no resolver, once with a TLS interval shorter than the time between checks and once longer, and expects one more warning after each check.

  • Judgement call: TestTLSExpiryWarningDedup, which ran two checks against live DNS and expected the second to send no warning, is replaced by the new test; TestTLSExpiryWarning still covers one check against live DNS.
  • Judgement call: a target listed twice in DNSWATCHER_TARGETS now gets two expiry warnings per check, which the removed record used to hide; filed as #207 rather than guarded here.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/dnswatcher/issues/204, following the plan in https://git.eeqj.de/sneak/dnswatcher/issues/204#issuecomment-110063. An expiry warning was skipped when the last one for the same hostname and address had been sent less than `DNSWATCHER_TLS_INTERVAL` ago. Each TLS check runs after a DNS pass of varying length, so two checks can be less than the interval apart, and a certificate about to expire was warned about on every check or every other check, at random. That record of when each warning was sent is removed: every TLS check now warns once per hostname and address while the certificate is within the warning period, which is what the README already says ("repeated each check until renewed or expired"), so the README is unchanged. TLS checks start once per `DNSWATCHER_TLS_INTERVAL`, so this is still about one warning per interval. The removed record was held only in memory, so nothing in the state file changes. The new test runs the TLS checks three times on hostname and port state built in the test, with no resolver, once with a TLS interval shorter than the time between checks and once longer, and expects one more warning after each check. - Judgement call: `TestTLSExpiryWarningDedup`, which ran two checks against live DNS and expected the second to send no warning, is replaced by the new test; `TestTLSExpiryWarning` still covers one check against live DNS. - Judgement call: a target listed twice in `DNSWATCHER_TARGETS` now gets two expiry warnings per check, which the removed record used to hide; filed as https://git.eeqj.de/sneak/dnswatcher/issues/207 rather than guarded here. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 01:48:31 +02:00
clawbot self-assigned this 2026-10-02 01:48:31 +02:00
Author
Collaborator

Review passed on 0a0afb8.

Model: opus-5-5

Review passed on 0a0afb8. Model: opus-5-5
clawbot added 1 commit 2026-10-02 01:58:08 +02:00
An expiry warning was skipped when the last one for that hostname and
address was sent less than DNSWATCHER_TLS_INTERVAL ago. Each TLS check
runs after a DNS pass of varying length, so two checks can be less than
the interval apart, and a certificate about to expire was warned about on
every check or every other check, at random. TLS checks already start
once per interval, so the in-memory record of when each warning was sent
is removed and every check warns, as the README says.

The test that expected the second check to stay silent is replaced by one
that runs TLS checks on state built in the test, with no DNS.

Model: opus-5-5
clawbot force-pushed issue-204-expiry-warning-rule from 0a0afb822a to 1c2f1ec158 2026-10-02 01:58:08 +02:00 Compare
clawbot merged commit c9510a986c into next 2026-10-02 01:58:28 +02:00
clawbot deleted branch issue-204-expiry-warning-rule 2026-10-02 01:58:29 +02:00
clawbot removed the needs-review label 2026-10-02 01:58:29 +02:00
Sign in to join this conversation.