reject an apex NS DNSRecord instead of appending to the live RRset
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

BIND ignores an RRset-wide delete at a zone apex, so a DNSRecord for the
apex NS can only add to what the zone was seeded with while reporting
success. BindZone.spec.nameservers converges it per rdata.
This commit is contained in:
2026-09-27 10:58:45 +10:00
parent 057575b9b5
commit afb4fe2631
6 changed files with 56 additions and 3 deletions
+26
View File
@@ -77,3 +77,29 @@ func TestCatalogEnabledDefault(t *testing.T) {
t.Error("secondary zone should never be a catalog member")
}
}
func TestIsApexNS(t *testing.T) {
const zone = "acme.unkin.net"
cases := []struct {
name, typ string
want bool
}{
{"@", "NS", true},
{"", "NS", true},
{"acme.unkin.net.", "NS", true},
{"ACME.UNKIN.NET.", "ns", true},
{"@", "ns", true},
// No trailing dot means relative: acme.unkin.net.acme.unkin.net.
{"acme.unkin.net", "NS", false},
{"sub", "NS", false},
{"ns1", "NS", false},
{"@", "TXT", false},
{"@", "MX", false},
{"@", "SOA", false},
}
for _, c := range cases {
if got := isApexNS(c.name, c.typ, zone); got != c.want {
t.Errorf("isApexNS(%q,%q)=%v want %v", c.name, c.typ, got, c.want)
}
}
}