check / check (push) Successful in 4m6s
The canonical files are fetched whole from sneak/prompts at dd4027b. Kept after the canonical content: the livednstest deny entry in .golangci.yml, /bin in .dockerignore, this repo's own .gitignore lines and a [*.go] tab section in .editorconfig. The workflow keeps its concurrency block and persist-credentials: false. Lint and test are phases of the Dockerfile (golangci-lint v2.14.0; tests on the Debian Go 1.25.7 image as an ordinary user, with the same flags); the build stage depends on both and stamps the version the canonical way. Dockerfile.lint is gone; the prettier stages of Dockerfile.fmt moved into the Dockerfile. Every scripted docker build passes --no-cache; script/cibuild bootstraps, runs script/check, then builds the image. script/fmt-check absorbs fmt-check-go and fmt-check-markdown. Model: opus-5-5
45 lines
1.9 KiB
Markdown
45 lines
1.9 KiB
Markdown
# Testing Policy
|
||
|
||
## DNS Resolution Tests
|
||
|
||
DNS is never mocked in this project, not in tests and not anywhere else; see the
|
||
README section "No DNS mocking. Ever." Every test that looks something up in DNS
|
||
**MUST** query live DNS servers, never a stand-in. Logic that works on record
|
||
data, such as comparing or formatting records, may be tested on that data
|
||
directly with no lookup.
|
||
|
||
### Rationale
|
||
|
||
The resolver performs iterative resolution from root nameservers through the
|
||
full delegation chain. Mocked responses cannot faithfully represent the variety
|
||
of real-world DNS behavior (truncation, referrals, glue records, DNSSEC, varied
|
||
response times, EDNS, etc.). Testing against real servers ensures the resolver
|
||
works correctly in production.
|
||
|
||
### Constraints
|
||
|
||
- Tests hit real DNS infrastructure and require network access
|
||
- Test duration depends on network conditions; timeout tuning keeps the suite
|
||
within the 60-second target
|
||
- Query timeout is calibrated to 3× maximum antipodal RTT (~300ms) plus
|
||
processing margin
|
||
- Root server fan-out is limited to reduce parallel query load
|
||
- Live lookups that expect an answer go through `internal/livednstest`, which
|
||
limits how many run at once in a test binary and retries a lookup that got
|
||
none
|
||
- Flaky failures from transient network issues are acceptable and should be
|
||
investigated as potential resolver bugs, not papered over with mocks or skip
|
||
flags
|
||
|
||
### What NOT to do
|
||
|
||
- **Do not mock, fake or stub DNS** anywhere: no stand-in `DNSClient`, no
|
||
stand-in for the watcher's `DNSResolver`, no fake DNS server, no canned
|
||
responses
|
||
- **Do not add `-short` flags** to skip slow tests
|
||
- **Do not increase `-timeout`** to hide hanging queries
|
||
- **Do not remove `-count=1` from the test phase of the `Dockerfile`** — Go's
|
||
test cache replays a previous run's output without querying anything, so a
|
||
cached pass is not evidence that live resolution works
|
||
- **Do not modify linter configuration** to suppress findings
|