The resolver answers on an address systemd does not hold
`127.0.0.54` is systemd-resolved's DNS *proxy* stub. The module asserted it was free, in a comment that read as reasoned — "not .53, that is systemd-resolved's" — and it was simply wrong: resolved holds both. dnsmasq could not create the socket and never started. Nothing in a unit test could have caught it. They checked the module names an address and that the asking modules point at the same one, and all of that passed while the daemon could not start. Only a machine knows which addresses are spare, which is the argument for proving a module that asserts facts about machines on a machine, before believing the assertions. So it moves to .55, and says what that is: a convention, not a reservation. If a future systemd takes it, this line changes and nothing else does. The tests now derive the address from the serving module and check the two asking modules agree with it, rather than naming it a fourth time — that fourth place is the one nobody would think to change. And the lab assigns `resolved-split-dns` rather than `resolv-conf`: those machines run systemd-resolved, which owns the file. The two claim the same thing precisely so the wrong choice is a refusal rather than a fight, and picking the wrong one was testing the fight.
This commit is contained in:
@@ -7,6 +7,6 @@
|
||||
|
||||
"resources": [
|
||||
{"id": "resolv", "type": "file", "path": "/etc/resolv.conf", "mode": "0644",
|
||||
"content": "# Managed by the mesh.\n#\n# For a machine where nothing else owns this file. On one where systemd-resolved\n# or NetworkManager does, assign that module instead — this one and those claim\n# the same thing, so the mesh refuses the pair rather than letting them take\n# turns overwriting each other, which is the failure this claim exists to stop.\n#\n# The mesh's resolver first, because it answers only the mesh's names and\n# forwards nothing: a query it does not recognise falls through to the next\n# line rather than being answered wrongly.\nnameserver 127.0.0.54\n\n# And what this machine used before. Replace this line with the resolver this\n# machine should use for everything that is not the mesh — it is not the mesh's\n# to choose, and a public one written here by default would send every query\n# this machine makes somewhere nobody agreed to.\nnameserver 127.0.0.53\n"}
|
||||
"content": "# Managed by the mesh.\n#\n# For a machine where nothing else owns this file. On one where systemd-resolved\n# or NetworkManager does, assign that module instead — this one and those claim\n# the same thing, so the mesh refuses the pair rather than letting them take\n# turns overwriting each other, which is the failure this claim exists to stop.\n#\n# The mesh's resolver first, because it answers only the mesh's names and\n# forwards nothing: a query it does not recognise falls through to the next\n# line rather than being answered wrongly.\nnameserver 127.0.0.55\n\n# And what this machine used before. Replace this line with the resolver this\n# machine should use for everything that is not the mesh — it is not the mesh's\n# to choose, and a public one written here by default would send every query\n# this machine makes somewhere nobody agreed to.\nnameserver 127.0.0.53\n"}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user