check / check (push) Failing after 2m1s
When a watched name's nameservers answer with a CNAME and no address, the DNS check asks ResolveIPAddresses for the name, which looks it up again and follows the chain, and saves the addresses at its end in the hostname state as cnameAddresses. The port and TLS checks use them. Before, a CNAME into another zone got no port or TLS checks. A change in those addresses is notified as a CNAME address change. When following fails, or none of the name's nameservers answered, the addresses the last check saved are kept. The domain check now runs the hostname check for the apex instead of a copy of it. Model: opus-5-5
95 lines
2.2 KiB
Go
95 lines
2.2 KiB
Go
package watcher
|
|
|
|
import (
|
|
"context"
|
|
"log/slog"
|
|
"time"
|
|
|
|
"sneak.berlin/go/dnswatcher/internal/config"
|
|
"sneak.berlin/go/dnswatcher/internal/resolver"
|
|
"sneak.berlin/go/dnswatcher/internal/state"
|
|
)
|
|
|
|
// NewForTest creates a Watcher without fx for unit testing.
|
|
func NewForTest(
|
|
cfg *config.Config,
|
|
st *state.State,
|
|
res DNSResolver,
|
|
pc PortChecker,
|
|
tc TLSChecker,
|
|
n Notifier,
|
|
) *Watcher {
|
|
return &Watcher{
|
|
log: slog.Default(),
|
|
config: cfg,
|
|
state: st,
|
|
resolver: res,
|
|
portCheck: pc,
|
|
tlsCheck: tc,
|
|
notify: n,
|
|
firstRun: true,
|
|
}
|
|
}
|
|
|
|
// NewlyDisagreeingPairs exports newlyDisagreeingPairs for testing.
|
|
func NewlyDisagreeingPairs(
|
|
prev, current *state.HostnameState,
|
|
) [][2]string {
|
|
return newlyDisagreeingPairs(prev, current)
|
|
}
|
|
|
|
// DetectHostnameChanges exports detectHostnameChanges for testing.
|
|
func (w *Watcher) DetectHostnameChanges(
|
|
ctx context.Context,
|
|
hostname string,
|
|
prev, current *state.HostnameState,
|
|
) {
|
|
w.detectHostnameChanges(ctx, hostname, prev, current)
|
|
}
|
|
|
|
// ResolveNameserverAddresses exports resolveNameserverAddresses for
|
|
// testing.
|
|
func (w *Watcher) ResolveNameserverAddresses(
|
|
ctx context.Context,
|
|
nameservers []string,
|
|
prev map[string][]string,
|
|
) map[string][]string {
|
|
return w.resolveNameserverAddresses(ctx, nameservers, prev)
|
|
}
|
|
|
|
// ResolveCNAMEAddresses exports resolveCNAMEAddresses for testing.
|
|
func (w *Watcher) ResolveCNAMEAddresses(
|
|
ctx context.Context,
|
|
hostname string,
|
|
current, prev *state.HostnameState,
|
|
) {
|
|
w.resolveCNAMEAddresses(ctx, hostname, current, prev)
|
|
}
|
|
|
|
// DetectNSAddressChanges exports detectNSAddressChanges for testing.
|
|
func (w *Watcher) DetectNSAddressChanges(
|
|
ctx context.Context,
|
|
domain string,
|
|
prev, current map[string][]string,
|
|
) {
|
|
w.detectNSAddressChanges(ctx, domain, prev, current)
|
|
}
|
|
|
|
// CheckAllPorts exports checkAllPorts for testing.
|
|
func (w *Watcher) CheckAllPorts(ctx context.Context) {
|
|
w.checkAllPorts(ctx)
|
|
}
|
|
|
|
// RunTLSChecks exports runTLSChecks for testing.
|
|
func (w *Watcher) RunTLSChecks(ctx context.Context) {
|
|
w.runTLSChecks(ctx)
|
|
}
|
|
|
|
// BuildHostnameState exports buildHostnameState for testing.
|
|
func BuildHostnameState(
|
|
results map[string]*resolver.NameserverResponse,
|
|
now time.Time,
|
|
) *state.HostnameState {
|
|
return buildHostnameState(results, now)
|
|
}
|