feat: rework engine and CLI for dnstraverse parity

Port the traversal engine to the Ruby dnstraverse model so behaviour and
output match dns.squish.net:

- dns: single RD=0 query path (RD=1 only for upstream root discovery),
  per-run packet cache, EDNS0 512-fallback with warnings, UDP->TCP on
  truncation; fix --retries 0 and --root-server IP-literal handling;
  drop all hardcoded 127.0.0.1:53 resolvers
- traverse: hierarchical per-branch InfoCache, 7-step response
  classification with the full 10-status vocabulary, bailiwick
  partitioning, strictly-deeper lame-referral rule, refid grammar with
  .0 resolve subtrees and childset digits, per-IP branching at 1/n
  weight, cache-based glue resolution with noglue/loop dead ends, CNAME
  restarts from the deepest cached zone, fast-mode memoization,
  probability aggregation with Ruby-identical stats keys (sums to 1.0)
- output: byte-for-byte reference text format pinned by a golden test,
  reference CLI defaults, working --quiet/--show-X=false, TTY-aware
  colour, deduplicated deterministic JSON
- web: adapt API/SPA to the new engine, SSE events carry refid/status,
  fix subscribe/snapshot duplicate-event race and a statusCls TDZ bug,
  align SPA type list with the backend
- delete the old engine and dead code (net -4,350 lines)

Verified against live runs of the reference Ruby engine across five
domains (answers, NXDOMAIN, null MX, CNAME restart, glueless resolve)
with no divergences beyond the documented typo fixes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Gary Hansen
2026-07-07 21:42:06 +10:00
co-authored by Claude Fable 5
parent af15c9c2d4
commit d71c7fbef2
53 changed files with 6685 additions and 9366 deletions
+176 -141
View File
@@ -1,159 +1,194 @@
package traverse
import (
"net"
"testing"
"gitea.hansenits.com.au/hits/ExploreDNS/internal/dns"
"github.com/miekg/dns"
)
const TypeA = dns.TypeA
type State = ResolutionState
func TestNewReferral(t *testing.T) {
ref := NewReferral("example.com", TypeA, ".", 0, 1.0, nil)
if ref.Name != "example.com." {
t.Errorf("Name = %q, want %q", ref.Name, "example.com.")
func newTestReferral(server string, ips []string) *Referral {
r := &Referral{
RefID: "1",
Qname: "www.example.com",
Qclass: dns.ClassINET,
Qtype: dns.TypeA,
NSAType: dns.TypeA,
Server: server,
ServerIPs: ips,
Bailiwick: "com",
InfoCache: NewInfoCache(nil),
Status: RefStatusNormal,
Responses: make(map[string]*ServerResponse),
Children: make(map[string][]*Referral),
ServerWeights: make(map[string]float64),
maxdepth: DefaultMaxDepth,
}
if ref.Qtype != TypeA {
t.Errorf("Qtype = %d, want %d", ref.Qtype, TypeA)
}
if ref.Qclass != 1 {
t.Errorf("Qclass = %d, want 1", ref.Qclass)
}
if ref.State != StateUnresolved {
t.Errorf("State = %d, want %d", ref.State, StateUnresolved)
}
if ref.Depth != 0 {
t.Errorf("Depth = %d, want 0", ref.Depth)
}
if ref.Prob != 1.0 {
t.Errorf("Prob = %f, want 1.0", ref.Prob)
}
if ref.Parent != nil {
t.Error("Parent should be nil")
for _, ip := range ips {
r.ServerWeights[ip] = 1.0 / float64(len(ips))
}
return r
}
func TestReferralInBailiwick(t *testing.T) {
func TestRefidDepth(t *testing.T) {
tests := []struct {
name string
bailiwick string
testName string
want bool
refid string
want int
}{
{"root bailiwick accepts all", ".", "example.com.", true},
{"empty bailiwick accepts all", "", "example.com.", true},
{"subdomain in bailiwick", "com.", "example.com.", true},
{"deeper subdomain", "com.", "www.example.com.", true},
{"not in bailiwick", "org.", "example.com.", false},
{"same zone", "example.com.", "example.com.", true},
{"sibling zone", "example.com.", "other.com.", false},
{"", 0},
{"1", 1},
{"1.1.2", 3},
{"1.2.0.1", 3},
{"1.1.2.0.1.4.2.0.2.0.2", 8},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
ref := &Referral{Bailiwick: tt.bailiwick}
if got := ref.InBailiwick(tt.testName); got != tt.want {
t.Errorf("InBailiwick(%q) = %v, want %v", tt.testName, got, tt.want)
}
})
}
}
func TestReferralHasAddresses(t *testing.T) {
ref := &Referral{}
if ref.HasAddresses() {
t.Error("empty referral should not have addresses")
}
ref.Addresses = []net.IP{net.ParseIP("1.2.3.4")}
if !ref.HasAddresses() {
t.Error("referral with address should have addresses")
}
}
func TestReferralSetAddresses(t *testing.T) {
ref := &Referral{}
ref.SetAddresses([]net.IP{net.ParseIP("1.2.3.4")})
if ref.State != StateResolved {
t.Errorf("State = %d, want %d", ref.State, StateResolved)
}
if !ref.HasAddresses() {
t.Error("should have addresses after SetAddresses")
}
ref.SetAddresses(nil)
if ref.State != StateUnresolved {
t.Errorf("State = %d, want %d", ref.State, StateUnresolved)
}
}
func TestResolutionStateString(t *testing.T) {
tests := []struct {
state State
want string
}{
{StateUnresolved, "unresolved"},
{StateResolving, "resolving"},
{StateResolved, "resolved"},
}
for _, tt := range tests {
t.Run(tt.want, func(t *testing.T) {
if got := tt.state.String(); got != tt.want {
t.Errorf("String() = %q, want %q", got, tt.want)
}
})
}
}
func TestCircularReferralError(t *testing.T) {
err := &CircularReferralError{
Name: "ns.example.com.",
Chain: []string{"ns1.example.com.", "ns2.example.com."},
}
expected := "circular referral detected for ns.example.com.: [ns1.example.com. ns2.example.com.]"
if err.Error() != expected {
t.Errorf("Error() = %q, want %q", err.Error(), expected)
}
}
func TestUnresolvableNameserverError(t *testing.T) {
err := &UnresolvableNameserverError{
Name: "ns.example.com.",
Reason: "NXDOMAIN",
}
expected := "unresolvable nameserver ns.example.com.: NXDOMAIN"
if err.Error() != expected {
t.Errorf("Error() = %q, want %q", err.Error(), expected)
}
}
func TestGetVisitedNames(t *testing.T) {
visited := map[string]bool{
"ns1.example.com.": true,
"ns2.example.com.": true,
"ns3.example.com.": true,
}
names := getVisitedNames(visited)
if len(names) != 3 {
t.Errorf("got %d names, want 3", len(names))
}
seen := make(map[string]bool)
for _, name := range names {
if seen[name] {
t.Errorf("duplicate name: %s", name)
}
seen[name] = true
if !visited[name] {
t.Errorf("unexpected name: %s", name)
if got := refidDepth(tt.refid); got != tt.want {
t.Errorf("refidDepth(%q) = %d, want %d", tt.refid, got, tt.want)
}
}
}
func TestTxtIPsVerbose(t *testing.T) {
r := newTestReferral("ns1.example.com", []string{"2.2.2.2", "1.1.1.1"})
if got := r.TxtIPsVerbose(); got != "50.0%=1.1.1.1,50.0%=2.2.2.2" {
t.Errorf("TxtIPsVerbose = %q", got)
}
// key: pseudo entries keep only the first two fields.
r2 := newTestReferral("ns2.example.com", nil)
r2.ServerIPs = []string{"key:noglue:9.9.9.9:www.example.com:IN:A:x:y"}
r2.ServerWeights = map[string]float64{r2.ServerIPs[0]: 1.0}
if got := r2.TxtIPsVerbose(); got != "100.0%=noglue:9.9.9.9" {
t.Errorf("TxtIPsVerbose key entry = %q", got)
}
var unresolved Referral
if got := unresolved.TxtIPsVerbose(); got != "" {
t.Errorf("unresolved TxtIPsVerbose = %q, want empty", got)
}
}
func TestFastKeyLowercases(t *testing.T) {
r := newTestReferral("NS1.Example.COM", []string{"1.1.1.1"})
r.Server = "NS1.Example.COM" // bypass canonicalisation to prove downcasing
key := fastKey(r)
if key != "www.example.com:in:a:ns1.example.com:100.0%=1.1.1.1" {
t.Errorf("fastKey = %q", key)
}
}
func TestIsNoGlueAndIsLoop(t *testing.T) {
inBailiwick := newTestReferral("ns1.sub.com", nil)
if !inBailiwick.isNoGlue() {
t.Error("in-bailiwick NS without addresses should be noglue")
}
outOfBailiwick := newTestReferral("ns1.other.net", nil)
if outOfBailiwick.isNoGlue() {
t.Error("out-of-bailiwick NS is resolvable, not noglue")
}
resolved := newTestReferral("ns1.sub.com", []string{"1.1.1.1"})
if resolved.isNoGlue() || resolved.isLoop() {
t.Error("resolved referral is neither noglue nor loop")
}
parent := newTestReferral("ns.b.net", nil)
parent.Qname = "ns.a.net"
child := newTestReferral("ns.b.net", nil)
child.Qname = "ns.a.net"
child.Parent = parent
if !child.isLoop() {
t.Error("same qname/qclass/qtype/server with unresolved ancestor should loop")
}
child.Server = "ns.c.net"
if child.isLoop() {
t.Error("different server must not loop")
}
}
func TestChainHasQuery(t *testing.T) {
parent := newTestReferral("ns1.example.com", []string{"1.1.1.1"})
parent.Qname = "www.a.com"
child := newTestReferral("ns2.example.com", []string{"2.2.2.2"})
child.Qname = "www.b.net"
child.Parent = parent
if !child.chainHasQuery("www.a.com") {
t.Error("ancestor qname should be found")
}
if !child.chainHasQuery("WWW.B.NET.") {
t.Error("own qname should be found case-insensitively")
}
if child.chainHasQuery("www.c.org") {
t.Error("unknown qname must not match")
}
}
func TestReplaceChild(t *testing.T) {
parent := newTestReferral("ns1.example.com", []string{"1.1.1.1"})
before := newTestReferral("ns2.example.com", []string{"2.2.2.2"})
after := newTestReferral("ns2.example.com", []string{"2.2.2.2"})
parent.Children["1.1.1.1"] = []*Referral{before}
parent.Resolves = []*Referral{before}
parent.replaceChild(before, after)
if parent.Children["1.1.1.1"][0] != after || parent.Resolves[0] != after {
t.Error("replaceChild did not swap the node everywhere")
}
if before.ReplacedBy != after {
t.Error("replaced node should point at its replacement")
}
}
func TestOverallStatus(t *testing.T) {
r := newTestReferral("ns1.example.com", nil)
r.Status = RefStatusNoGlue
if got := r.OverallStatus(); got != StatusNoGlue {
t.Errorf("noglue overall = %q", got)
}
r.Status = RefStatusLoop
if got := r.OverallStatus(); got != StatusLoop {
t.Errorf("loop overall = %q", got)
}
n := newTestReferral("ns1.example.com", []string{"1.1.1.1", "2.2.2.2"})
if got := n.OverallStatus(); got != "" {
t.Errorf("no responses overall = %q, want empty", got)
}
n.Responses["1.1.1.1"] = &ServerResponse{Status: StatusAnswered}
if got := n.OverallStatus(); got != StatusAnswered {
t.Errorf("single status overall = %q", got)
}
n.Responses["2.2.2.2"] = &ServerResponse{Status: StatusError}
if got := n.OverallStatus(); got != "mixed" {
t.Errorf("mixed overall = %q", got)
}
}
func TestIPsAsArraySkipsPseudoKeys(t *testing.T) {
r := newTestReferral("ns1.example.com", []string{"1.1.1.1", "key:noglue:2.2.2.2"})
got := r.IPsAsArray()
if len(got) != 1 || got[0] != "1.1.1.1" {
t.Errorf("IPsAsArray = %v", got)
}
}
func TestToASCII(t *testing.T) {
if got := toASCII("bücher.example"); got != "xn--bcher-kva.example" {
t.Errorf("toASCII = %q", got)
}
if got := toASCII("plain.example"); got != "plain.example" {
t.Errorf("ascii name changed: %q", got)
}
if got := toASCII(""); got != "" {
t.Errorf("empty name changed: %q", got)
}
}
func TestServerResponseString(t *testing.T) {
noglue := NewNoGlueResponse("www.example.com", dns.ClassINET, dns.TypeA, "1.1.1.1", "ns1.example.com", "example.com")
if got := noglue.String(); got != "No glue for ns1.example.com" {
t.Errorf("noglue String = %q", got)
}
loop := NewLoopResponse("www.example.com", dns.ClassINET, dns.TypeA, "1.1.1.1", "ns1.example.com", "example.com")
if got := loop.String(); got != "Loop encountered resolving ns1.example.com" {
t.Errorf("loop String = %q", got)
}
}