feat: rework engine and CLI for dnstraverse parity

Port the traversal engine to the Ruby dnstraverse model so behaviour and
output match dns.squish.net:

- dns: single RD=0 query path (RD=1 only for upstream root discovery),
  per-run packet cache, EDNS0 512-fallback with warnings, UDP->TCP on
  truncation; fix --retries 0 and --root-server IP-literal handling;
  drop all hardcoded 127.0.0.1:53 resolvers
- traverse: hierarchical per-branch InfoCache, 7-step response
  classification with the full 10-status vocabulary, bailiwick
  partitioning, strictly-deeper lame-referral rule, refid grammar with
  .0 resolve subtrees and childset digits, per-IP branching at 1/n
  weight, cache-based glue resolution with noglue/loop dead ends, CNAME
  restarts from the deepest cached zone, fast-mode memoization,
  probability aggregation with Ruby-identical stats keys (sums to 1.0)
- output: byte-for-byte reference text format pinned by a golden test,
  reference CLI defaults, working --quiet/--show-X=false, TTY-aware
  colour, deduplicated deterministic JSON
- web: adapt API/SPA to the new engine, SSE events carry refid/status,
  fix subscribe/snapshot duplicate-event race and a statusCls TDZ bug,
  align SPA type list with the backend
- delete the old engine and dead code (net -4,350 lines)

Verified against live runs of the reference Ruby engine across five
domains (answers, NXDOMAIN, null MX, CNAME restart, glueless resolve)
with no divergences beyond the documented typo fixes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Gary Hansen
2026-07-07 21:42:06 +10:00
co-authored by Claude Fable 5
parent af15c9c2d4
commit d71c7fbef2
53 changed files with 6685 additions and 9366 deletions
+135 -94
View File
@@ -1,6 +1,7 @@
package traverse
import (
"fmt"
"net"
"strings"
"sync"
@@ -8,117 +9,157 @@ import (
miekgdns "github.com/miekg/dns"
)
// StartServer is one entry returned by GetStartServers: a nameserver hostname
// plus its cached IPv4 addresses. IPs == nil means no addresses are cached and
// the caller must resolve the name itself (glueless).
type StartServer struct {
Name string
IPs []string
}
// InfoCache is the hierarchical per-branch record cache (info_cache.rb). Each
// response wraps its parent's cache in a child so sibling branches never see
// each other's records; lookups recurse towards the root cache.
type InfoCache struct {
parent *InfoCache
mu sync.RWMutex
ns map[string][]string
glue map[string][]net.IP
data map[string][]miekgdns.RR
}
func NewInfoCache(parent *InfoCache) *InfoCache {
return &InfoCache{
parent: parent,
ns: make(map[string][]string),
glue: make(map[string][]net.IP),
data: make(map[string][]miekgdns.RR),
}
}
func (c *InfoCache) StoreNS(zone string, nameservers []string) {
if len(nameservers) == 0 {
return
}
zone = normalize(zone)
c.mu.Lock()
seen := make(map[string]bool)
for _, ns := range nameservers {
ns = normalize(ns)
if !seen[ns] {
seen[ns] = true
c.ns[zone] = append(c.ns[zone], ns)
}
}
c.mu.Unlock()
}
func (c *InfoCache) LookupNS(zone string) []string {
zone = normalize(zone)
if names := c.localNS(zone); len(names) > 0 {
return names
}
if c.parent != nil {
return c.parent.LookupNS(zone)
}
return nil
}
func (c *InfoCache) localNS(zone string) []string {
c.mu.RLock()
defer c.mu.RUnlock()
names, ok := c.ns[zone]
if !ok {
return nil
}
result := make([]string, len(names))
copy(result, names)
return result
}
func (c *InfoCache) StoreGlue(name string, addrs []net.IP) {
if len(addrs) == 0 {
return
}
name = normalize(name)
c.mu.Lock()
seen := make(map[string]bool)
for _, addr := range addrs {
key := addr.String()
if !seen[key] {
seen[key] = true
c.glue[name] = append(c.glue[name], addr)
}
}
c.mu.Unlock()
}
func (c *InfoCache) LookupGlue(name string) []net.IP {
name = normalize(name)
if addrs := c.localGlue(name); len(addrs) > 0 {
return addrs
}
if c.parent != nil {
return c.parent.LookupGlue(name)
}
return nil
}
func (c *InfoCache) localGlue(name string) []net.IP {
c.mu.RLock()
defer c.mu.RUnlock()
addrs, ok := c.glue[name]
if !ok {
return nil
}
result := make([]net.IP, len(addrs))
copy(result, addrs)
return result
}
func (c *InfoCache) Child() *InfoCache {
return NewInfoCache(c)
}
func (c *InfoCache) NSCount() int {
c.mu.RLock()
defer c.mu.RUnlock()
return len(c.ns)
// canonicalName lowercases a DNS name and strips the trailing dot; the root
// (and empty string) canonicalises to "", matching the Ruby engine's
// representation of "no bailiwick".
func canonicalName(name string) string {
return strings.TrimSuffix(strings.ToLower(name), ".")
}
func (c *InfoCache) GlueCount() int {
c.mu.RLock()
defer c.mu.RUnlock()
return len(c.glue)
func cacheKey(name string, qclass, qtype uint16) string {
return fmt.Sprintf("%s:%d:%d", canonicalName(name), qclass, qtype)
}
func normalize(name string) string {
return strings.ToLower(miekgdns.Fqdn(name))
func rrCacheKey(rr miekgdns.RR) string {
h := rr.Header()
return cacheKey(h.Name, h.Class, h.Rrtype)
}
// Add stores resource records, REPLACING any existing entries that share a
// name:class:type key (info_cache.rb add: clear pass, then append pass, so
// several records under one key in a single call are all kept).
func (c *InfoCache) Add(rrs []miekgdns.RR) {
c.mu.Lock()
defer c.mu.Unlock()
for _, rr := range rrs {
c.data[rrCacheKey(rr)] = nil
}
for _, rr := range rrs {
key := rrCacheKey(rr)
c.data[key] = append(c.data[key], rr)
}
}
// AddHints seeds NS records for domain ("" = root hints) plus A/AAAA records
// for each server that has known addresses (info_cache.rb add_hints).
func (c *InfoCache) AddHints(domain string, servers []StartServer) {
var rrs []miekgdns.RR
owner := miekgdns.Fqdn(canonicalName(domain))
for _, srv := range servers {
name := miekgdns.Fqdn(canonicalName(srv.Name))
rrs = append(rrs, &miekgdns.NS{
Hdr: miekgdns.RR_Header{Name: owner, Rrtype: miekgdns.TypeNS, Class: miekgdns.ClassINET},
Ns: name,
})
for _, ip := range srv.IPs {
addr := net.ParseIP(ip)
if addr == nil {
continue
}
if v4 := addr.To4(); v4 != nil {
rrs = append(rrs, &miekgdns.A{
Hdr: miekgdns.RR_Header{Name: name, Rrtype: miekgdns.TypeA, Class: miekgdns.ClassINET},
A: v4,
})
} else {
rrs = append(rrs, &miekgdns.AAAA{
Hdr: miekgdns.RR_Header{Name: name, Rrtype: miekgdns.TypeAAAA, Class: miekgdns.ClassINET},
AAAA: addr,
})
}
}
}
c.Add(rrs)
}
// Get returns the cached RRset for name/class/type, consulting parent caches
// on a local miss. Returns nil when nothing is cached anywhere in the chain.
func (c *InfoCache) Get(name string, qclass, qtype uint16) []miekgdns.RR {
key := cacheKey(name, qclass, qtype)
c.mu.RLock()
rrs, ok := c.data[key]
c.mu.RUnlock()
if ok {
out := make([]miekgdns.RR, len(rrs))
copy(out, rrs)
return out
}
if c.parent != nil {
return c.parent.Get(name, qclass, qtype)
}
return nil
}
// getNS finds the nearest cached NS RRset at or above domain, walking labels
// upward to the root (info_cache.rb get_ns?).
func (c *InfoCache) getNS(domain string) ([]miekgdns.RR, error) {
domain = canonicalName(domain)
for {
if rrs := c.Get(domain, miekgdns.ClassINET, miekgdns.TypeNS); len(rrs) > 0 {
return rrs, nil
}
if domain == "" {
return nil, fmt.Errorf("no nameservers available for %q -- no root hints set??", domain)
}
if i := strings.Index(domain, "."); i >= 0 {
domain = domain[i+1:]
} else {
domain = ""
}
}
}
// GetStartServers returns the servers to start querying for domain: the
// nearest cached NS RRset walking labels upward, each nameserver paired with
// its cached A addresses (nil when unknown). newbailiwick is the owner name of
// that NS RRset ("" for root).
func (c *InfoCache) GetStartServers(domain string) (starters []StartServer, newbailiwick string, err error) {
ns, err := c.getNS(domain)
if err != nil {
return nil, "", err
}
for _, rr := range ns {
nsrr, ok := rr.(*miekgdns.NS)
if !ok {
continue
}
name := canonicalName(nsrr.Ns)
var ips []string
for _, iprr := range c.Get(name, miekgdns.ClassINET, miekgdns.TypeA) {
if a, ok := iprr.(*miekgdns.A); ok {
ips = append(ips, a.A.String())
}
}
starters = append(starters, StartServer{Name: name, IPs: ips})
}
newbailiwick = canonicalName(ns[0].Header().Name)
return starters, newbailiwick, nil
}