rework/dnstraverse-parity #27

Merged
gary merged 6 commits from rework/dnstraverse-parity into main 2026-07-07 12:14:13 +00:00
6 Commits
Author SHA1 Message Date
Gary HansenandClaude Fable 5 874374f03f docs: record two-region Fly scaling (syd + iad)
CI / test (pull_request) Successful in 2m36s
CI / docker (pull_request) Has been skipped
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 22:08:07 +10:00
Gary HansenandClaude Fable 5 ccf0e6b0dc fix: data race on test DNS handler flag under -race
TestClientAgainstLocalServer captured RecursionDesired into a plain bool
from the miekg server handler goroutine and read it from the test
goroutine; the UDP round-trip gives no happens-before edge, so CI's
-race run flagged it. Use atomic.Bool.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 22:08:06 +10:00
Gary HansenandClaude Fable 5 ccfd3fd156 build: add Fly.io deployment process
CI / test (pull_request) Failing after 2m45s
CI / docker (pull_request) Has been skipped
fly.toml (Dockerfile.web, scale-to-zero in syd, /api/health checks),
make deploy / deploy-status targets, a Gitea workflow deploying on v*
tags or manual dispatch via FLY_API_TOKEN, and README instructions
covering first-time setup and the server's runtime env knobs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 21:50:30 +10:00
Gary HansenandClaude Fable 5 111b8bf48e feat(web): harden server for public exposure
- hard per-traversal deadline (EXPLOREDNS_JOB_TIMEOUT, default 5m) so
  every job reaches a terminal state; timed-out jobs report error with
  any partial results instead of masquerading as complete
- cap concurrent traversals (EXPLOREDNS_MAX_JOBS, default 8) returning
  429 when saturated
- CORS off by default (the embedded SPA is same-origin); opt in via
  EXPLOREDNS_CORS_ORIGIN

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 21:50:29 +10:00
Gary HansenandClaude Fable 5 d71c7fbef2 feat: rework engine and CLI for dnstraverse parity
Port the traversal engine to the Ruby dnstraverse model so behaviour and
output match dns.squish.net:

- dns: single RD=0 query path (RD=1 only for upstream root discovery),
  per-run packet cache, EDNS0 512-fallback with warnings, UDP->TCP on
  truncation; fix --retries 0 and --root-server IP-literal handling;
  drop all hardcoded 127.0.0.1:53 resolvers
- traverse: hierarchical per-branch InfoCache, 7-step response
  classification with the full 10-status vocabulary, bailiwick
  partitioning, strictly-deeper lame-referral rule, refid grammar with
  .0 resolve subtrees and childset digits, per-IP branching at 1/n
  weight, cache-based glue resolution with noglue/loop dead ends, CNAME
  restarts from the deepest cached zone, fast-mode memoization,
  probability aggregation with Ruby-identical stats keys (sums to 1.0)
- output: byte-for-byte reference text format pinned by a golden test,
  reference CLI defaults, working --quiet/--show-X=false, TTY-aware
  colour, deduplicated deterministic JSON
- web: adapt API/SPA to the new engine, SSE events carry refid/status,
  fix subscribe/snapshot duplicate-event race and a statusCls TDZ bug,
  align SPA type list with the backend
- delete the old engine and dead code (net -4,350 lines)

Verified against live runs of the reference Ruby engine across five
domains (answers, NXDOMAIN, null MX, CNAME restart, glueless resolve)
with no divergences beyond the documented typo fixes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 21:42:06 +10:00
Gary HansenandClaude Fable 5 af15c9c2d4 docs: add dnstraverse reference spec, rework design, and golden tooling
Reconstructed behaviour spec of dns.squish.net / Ruby dnstraverse 0.1.14
(inputs, traversal semantics, probability model, verbatim output formats,
sourced from the live site, Wayback captures, and the Ruby source), the
engine rework design that maps it onto Go, a point-in-time codebase review,
golden reference captures, and tools/golden/run-reference.sh for running
the reference Ruby engine locally (clone is gitignored, GPL-3 dev-only).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 21:41:47 +10:00