Repository navigation
feat: add SKIP_AUDIT modifier - #4971
Open
GZTimeWalker wants to merge 1 commit into
Open
GZTimeWalker wants to merge 1 commit into
GZTimeWalker wants to merge 1 commit into
Conversation
Some providers accept and serve records that their RecordAuditor rejects, so a zone cannot be managed even though every record is fine. Add a SKIP_AUDIT record modifier (skip_audit metadata); providers.AuditRecords() now omits tagged records before calling the provider's auditor.
Author
|
Maybe a more complete allowed set in the ALIDNS audit would be a better fix than an opt-out, since the API already accepts this record. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new metadata flag causes persistent differences in ClouDNS and GCore comparisons.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds an opt-in, per-record escape hatch for provider audits that reject otherwise accepted DNS records.
Changes:
- Adds the
SKIP_AUDITJavaScript modifier. - Filters tagged records before invoking provider auditors, including when all records are skipped.
| File | Description |
|---|---|
| pkg/providers/providers.go | Excludes tagged records from provider audits. |
| pkg/js/helpers.js | Defines and illustrates SKIP_AUDIT. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| // ) | ||
|
|
||
| // Skip the provider's record audit for this record (see providers.AuditRecords): | ||
| var SKIP_AUDIT = { skip_audit: "true" }; |
| // Records tagged with skip_audit (the SKIP_AUDIT modifier) are not audited. | ||
| auditable := make(models.Records, 0, len(rcs)) | ||
| for _, rc := range rcs { | ||
| if rc.Metadata["skip_audit"] != "true" { |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Problem
A provider's
RecordAuditorcan reject records that the provider's API actually accepts and serves. When that happens the whole zone becomes unmanageable, even though every record in it is fine, because the audit fails before any diffing takes place.Concrete case: ALIDNS's
labelConstraint(added in #4787) decodes punycode A-labels and rejects non-Chinese IDNs. A zone that already contains such a record — for examplexn--628h.play, which the ALIDNS API stores and serves as the ASCII labelxn--628h— can no longer be previewed or pushed.Solution
Add an opt-in, per-record
SKIP_AUDITmodifier. It tags the record withskip_auditmetadata, andproviders.AuditRecords()omits tagged records before calling the provider's auditor. Every provider gets the escape hatch without changing any of its audit checks.Notes
Changes