L1/L2/L4: cleanup + README operational guide
L1 — Replace hand-rolled atoi/parseUint with strconv.ParseUint wrapped
in mustParseUint. Hamilton's reasoning: the comment "strconv adds
overhead we don't need" is the Lauren-Bug shape — we already validated
the input. Until we hadn't, on a path we couldn't predict. Stdlib's
edge-case coverage is the safer default; the wrapper panics on
malformed input so any future regression surfaces in CI, not as a
silent 0 serial.
L2 — applyUpdate no longer mutates the caller's RR header TTL. miekg/
dns parses the UPDATE message into RRs the caller still owns; silently
rewriting hdr.Ttl was a hygiene smell with no current functional
consequence but a clear documentation issue. Now we dns.Copy() the RR
before any header mutation.
L4 — README expanded with an "Operational constraints" section
documenting the contracts and limits operators should understand
before relying on this in production:
- Single-process atomicity only (with rsync-race mitigation)
- Process-global MsgAcceptFunc override
- No-op UPDATE doesn't bump SOA (with touch-UPDATE workaround)
- SOA invariants enforced strictly (zero, multi, non-apex SOA all
refused)
- Serial counter NNNN=9999 rollover semantics
- TSIG replay window dependency on miekg/dns default
- Git commit failure logged at ERROR, not rolled back
- Per-key rate limit knobs
Every constraint maps to a Hamilton review finding; documenting the
contract in operator-facing prose closes the gap between code and
expectation that the review identified.
This commit is contained in:
parent
8d1477350a
commit
89993ca207
3 changed files with 120 additions and 28 deletions
|
|
@ -297,8 +297,13 @@ func applyUpdate(zone string, defaultTTL uint32, rrs []dns.RR, rr dns.RR) ([]dns
|
|||
log.Debugf("apex %s add refused", dns.TypeToString[hdr.Rrtype])
|
||||
return rrs, dns.RcodeRefused, false
|
||||
}
|
||||
// Hamilton L2: don't mutate the caller's RR header. miekg/dns
|
||||
// parses the UPDATE message into RRs the caller still owns;
|
||||
// silently rewriting their TTL is a hygiene smell. Copy first,
|
||||
// then apply our default if needed.
|
||||
if hdr.Ttl == 0 {
|
||||
hdr.Ttl = defaultTTL
|
||||
rr = dns.Copy(rr)
|
||||
rr.Header().Ttl = defaultTTL
|
||||
}
|
||||
before := len(rrs)
|
||||
rrs = addRRTo(rrs, rr)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue