Route every zone seed through a fail-closed journal check

This commit is contained in:
2026-09-19 22:55:27 +10:00
parent f1d47c8ff7
commit da679285f0
6 changed files with 384 additions and 52 deletions
+26 -3
View File
@@ -51,12 +51,35 @@ ns1 IN A %s
`, ns, origin, serial, ns, primaryIP)
}
// EnsureSeedZone makes path loadable without discarding live data: it probes
// the zone file and journal, moves aside whatever cannot load, and writes a
// skeleton only when there is nothing to preserve. Every caller that needs a
// zone database file on disk goes through here, never WriteSeedZone directly.
func (e *Executor) EnsureSeedZone(ctx context.Context, namespace, pod, zone, path, primaryIP string) error {
state, err := e.ZoneDiskState(ctx, namespace, pod, path)
if err != nil {
return err
}
plan := PlanSeed(state)
if plan.Blocked != "" {
return fmt.Errorf("seed zone %s: %s", zone, plan.Blocked)
}
if err := e.Quarantine(ctx, namespace, pod, path, plan); err != nil {
return err
}
if !plan.WriteSeed {
return nil
}
return e.WriteSeedZone(ctx, namespace, pod, zone, path, primaryIP, plan.Serial)
}
// WriteSeedZone writes a seed zone file to path, creating parent directories.
// It overwrites any existing file, so callers must clear it with PlanSeed
// first. This is a placeholder that is replaced once real records are loaded.
// It overwrites any existing file unconditionally: use EnsureSeedZone unless
// the caller has already run PlanSeed and acted on it.
func (e *Executor) WriteSeedZone(ctx context.Context, namespace, pod, zone, path, primaryIP string, serial int64) error {
content := renderSeedZone(zone, primaryIP, serial)
cmd := []string{"sh", "-c", fmt.Sprintf("mkdir -p \"$(dirname '%s')\" && cat > '%s'", path, path)}
q := shellQuote(path)
cmd := []string{"sh", "-c", fmt.Sprintf("mkdir -p \"$(dirname %s)\" && cat > %s", q, q)}
if out, err := e.Exec(ctx, namespace, pod, cmd, content); err != nil {
return fmt.Errorf("seed zone %s: %w (out: %s)", zone, err, out)
}