POST /webhook (bearer-token auth, strict validation, 1MB cap) and
/healthz stay open; everything under /admin requires basic auth
(RECEIVER_ADMIN_USER/PASSWORD, refuses to start without a password,
constant-time compares). Admin JSON APIs for the traversal log
(filters, pagination) and stats, plus an embedded dashboard: stat
cards, four Chart.js charts (lazy CDN load with graceful degradation),
filterable log with expandable summaries, auto-refresh. Fetches
resolve against location.origin so credentialed bookmark URLs work.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Dual-dialect store (SQLite via modernc.org, MySQL via go-sql-driver,
both pure Go) with order-tolerant start/complete upserts, filtered and
paginated listing, and aggregate queries (per-day, top domains, query
types, statuses, duration percentiles, top clients). Sender gains
optional EXPLOREDNS_WEBHOOK_TOKEN bearer auth; a round-trip test pins
receiver structs byte-compatible with the sender payloads.
Note: go directive moves to 1.25.0, required by modernc.org/sqlite.
CI reads the version from go.mod so GOTOOLCHAIN=local stays satisfied.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
--version/-V on the CLI, version in /api/health via Server.SetVersion,
Makefile/Dockerfile ldflags stamping from git describe, and a release
workflow on v* tags: both binaries for linux/darwin (amd64+arm64) and
windows/amd64 with SHA256SUMS attached to the Gitea release
(idempotent — reuses an existing hand-written release and skips
already-uploaded assets), plus version-tagged Docker images.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
TestClientAgainstLocalServer captured RecursionDesired into a plain bool
from the miekg server handler goroutine and read it from the test
goroutine; the UDP round-trip gives no happens-before edge, so CI's
-race run flagged it. Use atomic.Bool.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Port the traversal engine to the Ruby dnstraverse model so behaviour and
output match dns.squish.net:
- dns: single RD=0 query path (RD=1 only for upstream root discovery),
per-run packet cache, EDNS0 512-fallback with warnings, UDP->TCP on
truncation; fix --retries 0 and --root-server IP-literal handling;
drop all hardcoded 127.0.0.1:53 resolvers
- traverse: hierarchical per-branch InfoCache, 7-step response
classification with the full 10-status vocabulary, bailiwick
partitioning, strictly-deeper lame-referral rule, refid grammar with
.0 resolve subtrees and childset digits, per-IP branching at 1/n
weight, cache-based glue resolution with noglue/loop dead ends, CNAME
restarts from the deepest cached zone, fast-mode memoization,
probability aggregation with Ruby-identical stats keys (sums to 1.0)
- output: byte-for-byte reference text format pinned by a golden test,
reference CLI defaults, working --quiet/--show-X=false, TTY-aware
colour, deduplicated deterministic JSON
- web: adapt API/SPA to the new engine, SSE events carry refid/status,
fix subscribe/snapshot duplicate-event race and a statusCls TDZ bug,
align SPA type list with the backend
- delete the old engine and dead code (net -4,350 lines)
Verified against live runs of the reference Ruby engine across five
domains (answers, NXDOMAIN, null MX, CNAME restart, glueless resolve)
with no divergences beyond the documented typo fixes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Three bugs fixed:
1. processReferral was calling ResolveNS with ref.Name (the query domain,
e.g. '800adventures.com.au.') instead of ref.Bailiwick (the NS hostname,
e.g. 'ns-a.hansenits.com.'). This caused the sub-traversal to look up the
wrong name and always fail to find the nameserver's IP address.
2. In ResolveNS (and Referral.Resolve), child referrals whose name matched the
visited set were unconditionally skipped. When the .com TLD returns glue A
records for the target NS alongside its delegation, the child referral has
addresses and should be queried directly rather than skipped.
3. FormatRecord was prepending the DNS header fields and then appending
rr.String() which already includes those same fields, producing doubled
output like 'example.com. 300 IN A example.com. 300 IN A 1.2.3.4'.
Now simply returns rr.String().
Additional improvements:
- Results section deduplicates terminal results: same NS failure or same
(NS, answer) pair is merged with summed probability, avoiding the same
nameserver appearing 15 times with 6.7% each.
- Result lines now include the NS hostname (from Bailiwick) and use the
compact rdata format, e.g. '33% ns-a.hansenits.com answered with 13.54.63.231'.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: multica-agent <github@multica.ai>
Add text and JSON formatters with real-time progress via traverser hooks,
summary statistics, and CLI integration for --show-* and --json flags.
Co-authored-by: multica-agent <github@multica.ai>
Add Resolver interface, BasicResolver, and CachingResolver to internal/dns.
CachingResolver wraps any Resolver with an in-memory cache keyed by
(server IP, name, type, class). Cache entries respect DNS TTL from
responses, falling back to a configurable default TTL. Thread-safe
using sync.RWMutex. Includes Len, Clear, and PurgeExpired methods
for cache management.
Closes HAN-379 (Phase 2.2).
Co-authored-by: multica-agent <github@multica.ai>
Add RootServer struct and DiscoverRoots function that queries the local
resolver for NS records of the root zone, resolves each root name to
A/AAAA addresses, and returns a list of RootServer structs.
Supports:
- Default: discovers a single root server from local resolver
- --root-server override to target a specific root server
- --all-root-servers to discover all 13 root servers
- --root-aaaa flag to include IPv6 addresses
Includes unit tests for all helper functions and integration tests
that skip gracefully when no resolver is available.
Co-authored-by: multica-agent <github@multica.ai>