Files
dnswatcher/TESTING.md
T
clawbot e8b40062da
check / check (push) Successful in 4m6s
build: re-vendor canonical files from prompts dd4027b (closes #257)
The canonical files are fetched whole from sneak/prompts at dd4027b.
Kept after the canonical content: the livednstest deny entry in
.golangci.yml, /bin in .dockerignore, this repo's own .gitignore lines
and a [*.go] tab section in .editorconfig. The workflow keeps its
concurrency block and persist-credentials: false. Lint and test are
phases of the Dockerfile (golangci-lint v2.14.0; tests on the Debian
Go 1.25.7 image as an ordinary user, with the same flags); the build
stage depends on both and stamps the version the canonical way.
Dockerfile.lint is gone; the prettier stages of Dockerfile.fmt moved
into the Dockerfile. Every scripted docker build passes --no-cache;
script/cibuild bootstraps, runs script/check, then builds the image.
script/fmt-check absorbs fmt-check-go and fmt-check-markdown.

Model: opus-5-5
2026-10-06 04:29:48 +02:00

1.9 KiB
Raw Blame History

Testing Policy

DNS Resolution Tests

DNS is never mocked in this project, not in tests and not anywhere else; see the README section "No DNS mocking. Ever." Every test that looks something up in DNS MUST query live DNS servers, never a stand-in. Logic that works on record data, such as comparing or formatting records, may be tested on that data directly with no lookup.

Rationale

The resolver performs iterative resolution from root nameservers through the full delegation chain. Mocked responses cannot faithfully represent the variety of real-world DNS behavior (truncation, referrals, glue records, DNSSEC, varied response times, EDNS, etc.). Testing against real servers ensures the resolver works correctly in production.

Constraints

  • Tests hit real DNS infrastructure and require network access
  • Test duration depends on network conditions; timeout tuning keeps the suite within the 60-second target
  • Query timeout is calibrated to 3× maximum antipodal RTT (~300ms) plus processing margin
  • Root server fan-out is limited to reduce parallel query load
  • Live lookups that expect an answer go through internal/livednstest, which limits how many run at once in a test binary and retries a lookup that got none
  • Flaky failures from transient network issues are acceptable and should be investigated as potential resolver bugs, not papered over with mocks or skip flags

What NOT to do

  • Do not mock, fake or stub DNS anywhere: no stand-in DNSClient, no stand-in for the watcher's DNSResolver, no fake DNS server, no canned responses
  • Do not add -short flags to skip slow tests
  • Do not increase -timeout to hide hanging queries
  • Do not remove -count=1 from the test phase of the Dockerfile — Go's test cache replays a previous run's output without querying anything, so a cached pass is not evidence that live resolution works
  • Do not modify linter configuration to suppress findings