Skip to content

feat: add SKIP_AUDIT modifier - #4971

Open
GZTimeWalker wants to merge 1 commit into
DNSControl:mainfrom
GZTimeWalker:feat/skip-audit
Open

GZTimeWalker wants to merge 1 commit into
DNSControl:mainfrom
GZTimeWalker:feat/skip-audit

Conversation

@GZTimeWalker

Copy link
Copy Markdown

Problem

A provider's RecordAuditor can reject records that the provider's API actually accepts and serves. When that happens the whole zone becomes unmanageable, even though every record in it is fine, because the audit fails before any diffing takes place.

Concrete case: ALIDNS's labelConstraint (added in #4787) decodes punycode A-labels and rejects non-Chinese IDNs. A zone that already contains such a record — for example xn--628h.play, which the ALIDNS API stores and serves as the ASCII label xn--628h — can no longer be previewed or pushed.

Solution

Add an opt-in, per-record SKIP_AUDIT modifier. It tags the record with skip_audit metadata, and providers.AuditRecords() omits tagged records before calling the provider's auditor. Every provider gets the escape hatch without changing any of its audit checks.

D("example.com", REG_NONE, DnsProvider(DNS_ALIDNS),
    TXT("xn--628h.play", "...", TTL(86400), SKIP_AUDIT),
);

Notes

  • No provider audit is modified; the behavior is unchanged unless a record opts in.
  • Scope is per-record.
  • Tagging is metadata-only. Metadata is not part of ComparableV3, and ALIDNS diffs with diff2.ByRecord(..., nil), so the extra key does not affect diffing.
  • If every record is tagged, the auditor is simply called with an empty set.

Changes

  • pkg/js/helpers.js — add the SKIP_AUDIT record modifier (var SKIP_AUDIT = { skip_audit: "true" };).
  • pkg/providers/providers.go — AuditRecords() filters records whose metadata["skip_audit"] == "true".

Some providers accept and serve records that their RecordAuditor rejects, so a zone cannot be managed even though every record is fine. Add a SKIP_AUDIT record modifier (skip_audit metadata); providers.AuditRecords() now omits tagged records before calling the provider's auditor.
Copilot AI balanced review requested due to automatic review settings October 6, 2026 15:52
@GZTimeWalker

Copy link
Copy Markdown
Author

Maybe a more complete allowed set in the ALIDNS audit would be a better fix than an opt-out, since the API already accepts this record.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new metadata flag causes persistent differences in ClouDNS and GCore comparisons.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds an opt-in, per-record escape hatch for provider audits that reject otherwise accepted DNS records.

Changes:

  • Adds the SKIP_AUDIT JavaScript modifier.
  • Filters tagged records before invoking provider auditors, including when all records are skipped.
File Description
pkg/​providers/​providers.go Excludes tagged records from provider audits.
pkg/​js/​helpers.js Defines and illustrates SKIP_AUDIT.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/js/helpers.js
// )

// Skip the provider's record audit for this record (see providers.AuditRecords):
var SKIP_AUDIT = { skip_audit: "true" };
// Records tagged with skip_audit (the SKIP_AUDIT modifier) are not audited.
auditable := make(models.Records, 0, len(rcs))
for _, rc := range rcs {
if rc.Metadata["skip_audit"] != "true" {

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants