dnstest

package
v1.9.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: MIT Imports: 18 Imported by: 0

Documentation

Overview

Package dnstest runs fake DNS servers on loopback for tests: plain DNS over UDP and TCP, DNS over TLS, DNS over HTTPS, DNS over QUIC, and a server that never answers. Each counts the queries it sees.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Answer

func Answer(query []byte, truncated bool) ([]byte, bool)

Answer builds a response to query. A truncated response carries no answers. A full response to an A query carries one A record.

func CloseQuietly

func CloseQuietly(c io.Closer)

CloseQuietly closes c in a test helper, where a close error changes nothing.

func SelfSignedCert

func SelfSignedCert(t *testing.T, name string) (tls.Certificate, *x509.CertPool)

SelfSignedCert returns a certificate for name and a pool that trusts it.

func StartDoH

func StartDoH(t *testing.T) (hostPort string, roots *x509.CertPool, queries *atomic.Int32)

StartDoH serves DNS over HTTPS at /dns-query with httptest's certificate, which is valid for example.com.

func StartSilent

func StartSilent(t *testing.T) (hostPort string, queries *atomic.Int32)

StartSilent reads DNS queries on a loopback UDP port and never answers, like a resolver behind a firewall that drops packets.

Types

type DNS

type DNS struct {
	HostPort   string
	TCPQueries atomic.Int32
}

DNS answers A queries with 192.0.2.1 over TCP. Over UDP it only sets the truncation bit, so a lookup succeeds only if it retries over TCP.

func StartDNS

func StartDNS(t *testing.T) *DNS

type DoQ

type DoQ struct {
	HostPort   string
	Conns      atomic.Int32
	Queries    atomic.Int32
	NonzeroIDs atomic.Int32 // RFC 9250 requires message ID 0
	Unfinished atomic.Int32 // streams whose query had no FIN after it
}

DoQ counts what a DNS over QUIC server sees.

func StartDoQ

func StartDoQ(t *testing.T) (*DoQ, *tls.Config)

StartDoQ serves DNS over QUIC on loopback with a certificate for dns.test, answering on each stream the way RFC 9250 describes. Like AdGuard, it aborts the handshake with an alert for the name refuse.test.

type DoT

type DoT struct {
	HostPort string
	Roots    *x509.CertPool
	Queries  atomic.Int32
	Conns    atomic.Int32
}

DoT is a DNS over TLS server on loopback with a self-signed certificate for dns.test, which counts its connections and queries.

func StartDoT

func StartDoT(t *testing.T, oneShot bool) *DoT

StartDoT starts a DoT. With oneShot, the server closes each connection after its first answer.

func (*DoT) Config

func (f *DoT) Config() *tls.Config

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL