- hard per-traversal deadline (EXPLOREDNS_JOB_TIMEOUT, default 5m) so
every job reaches a terminal state; timed-out jobs report error with
any partial results instead of masquerading as complete
- cap concurrent traversals (EXPLOREDNS_MAX_JOBS, default 8) returning
429 when saturated
- CORS off by default (the embedded SPA is same-origin); opt in via
EXPLOREDNS_CORS_ORIGIN
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Port the traversal engine to the Ruby dnstraverse model so behaviour and
output match dns.squish.net:
- dns: single RD=0 query path (RD=1 only for upstream root discovery),
per-run packet cache, EDNS0 512-fallback with warnings, UDP->TCP on
truncation; fix --retries 0 and --root-server IP-literal handling;
drop all hardcoded 127.0.0.1:53 resolvers
- traverse: hierarchical per-branch InfoCache, 7-step response
classification with the full 10-status vocabulary, bailiwick
partitioning, strictly-deeper lame-referral rule, refid grammar with
.0 resolve subtrees and childset digits, per-IP branching at 1/n
weight, cache-based glue resolution with noglue/loop dead ends, CNAME
restarts from the deepest cached zone, fast-mode memoization,
probability aggregation with Ruby-identical stats keys (sums to 1.0)
- output: byte-for-byte reference text format pinned by a golden test,
reference CLI defaults, working --quiet/--show-X=false, TTY-aware
colour, deduplicated deterministic JSON
- web: adapt API/SPA to the new engine, SSE events carry refid/status,
fix subscribe/snapshot duplicate-event race and a statusCls TDZ bug,
align SPA type list with the backend
- delete the old engine and dead code (net -4,350 lines)
Verified against live runs of the reference Ruby engine across five
domains (answers, NXDOMAIN, null MX, CNAME restart, glueless resolve)
with no divergences beyond the documented typo fixes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>