Commit graph

4 commits

Author SHA1 Message Date
70c548284e feat: add NS TTL consistency and NS-target CNAME checks
All checks were successful
continuous-integration/drone/push Build is passing
continuous-integration/drone/tag Build is passing
Observe the NS RRset TTL from each parent server (ParentView.NSTTL) and
whether each NS target name is a CNAME alias (ChildNSView.CNAMETarget).
Two new rules judge the collected facts:

- delegation_ns_ttl_inconsistent: warns when parent servers disagree on
  the NS TTL, which indicates zone-data inconsistency between primaries.
- delegation_ns_is_cname: flags NS targets that are CNAME aliases as
  critical, per RFC 2181 §10.3 which forbids aliased NS names.
2026-05-16 21:32:05 +08:00
3366cebf7d refactor: always probe DNSKEY regardless of parent DS presence
Move the "skip DNSKEY when no parent DS" decision out of Collect and
into the rules, so the prober stays a pure observer. The dnskeyQueryRule
and dnskeyMatchesDSRule already return StatusUnknown when no parent DS
is present.
2026-05-16 13:18:30 +08:00
7e8faa7169 refactor: deduplicate primary parent view selection in Collect
Replace the inline loop with a call to the existing primaryParentView()
helper so the selection algorithm lives in exactly one place.
2026-05-16 13:14:08 +08:00
7e0f29075e Initial commit 2026-04-26 19:46:01 +07:00