code wiki / _hdl_build / nx_porkbun_dnssec_check.nx
nx_porkbun_dnssec_check.nx
buildroot/runtime/_hdl_build/nx_porkbun_dnssec_check.nx
about
nx_porkbun_dnssec_check.nx -- ask PORKBUN (the actual authority, over the sovereign TLS-1.2 client;
NO third-party resolver) whether DNSSEC is enabled on a domain, and PRINT the raw record set. Compares
the broken domain against the KNOWN-GOOD one: if andelinwest.com has DNSSEC and nishifamily.com does
not (or has a mismatched DS), that is why andelinwest "resolves on some networks, not others" while
nishifamily works everywhere -- DNSSEC-validating resolvers SERVFAIL a domain with a bad DS.
usage: nx_porkbun_dnssec_check <domain> [<domain> ...] (default: andelinwest.com nishifamily.com)
(run nx_secret_cli get porkbun first -> /tmp/nxsecret.out) license_tier: ORIGINAL
dependencies 1 imports · 0 importers
imports: nx_acme_porkbun.nx
imported by: nobody (leaf or entry point)
call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown
structs
| none |
consts
| 9 | const K_MAGIC_65536: i64 = 65536 |
| 10 | const K_MAGIC_4194304: i64 = 4194304 |
functions
| 12 | func dc_pp(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 } |
| 13 | func dc_pe(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(2,s,n); return 0 } called by 1: main |
| 14 | func dc_slen(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} return n } |
| 15 | func dc_contains(hay: *u8, n: i64, needle: *u8) -> i64 |
| 22 | func dc_creds(ak: *i64, akn: *i64, sk: *i64, skn: *i64) -> i64 called by 1: main |
| 38 | func dc_one(store: *TrustStore, now: i64, ak: *u8, akn: i64, sk: *u8, skn: i64, domain: *u8) -> i64 |
| 54 | func main(argc: i64, argv: *i64) -> i64 |