Skip to content

fix: Stop DNS zone serial numbers from moving backwards - #223

Merged
ecv merged 1 commit into
mainfrom
fix/soa-serial-keep
Oct 3, 2026
Merged

ecv merged 1 commit into
mainfrom
fix/soa-serial-keep

Conversation

@ecv

@ecv ecv commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Related to #101

Summary

A zone's serial number dropped back to that morning's value whenever its SOA record was rewritten, because each rewrite sent today's date plus 01 and PowerDNS counts up from the value it is sent. A rewrite now sends whichever is higher, the new value or the serial the zone already holds, so the serial only rises. This replaces the approach in #111, which changes a code path the operator no longer runs. Making the operator own the serial on every write comes after one writer per zone (#201).

Test plan

  • A held serial above today's default survives a rewrite
  • A held serial below today's default gives way to it
  • A zone with no SOA still starts from today's default
  • CI passes

Every rewrite of a zone's SOA record set sent today's date plus 01 as
the serial. PowerDNS bumps the serial it is sent, not the one it holds,
so a zone whose serial had climbed past that value dropped back to it
on the next rewrite.

Send the higher of the desired serial and the one PowerDNS already
holds. A zone with no SOA still starts from today's date plus 01, and
an explicit serial above the held one is still sent as is.

Related to #101
@ecv
ecv marked this pull request as ready for review October 3, 2026 03:00
@ecv
ecv requested a review from a team as a code owner October 3, 2026 03:00
@ecv
ecv enabled auto-merge October 3, 2026 03:00
@ecv

ecv commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

pr-adversary: merge, no findings. The clamp runs only on the rewrite path, cannot loop, and keeps the serial monotonic. The five-case test passes.

pr-conventions-reviewer: merge, no blocker or warning. Decisions settled: the change merges cleanly with #217 (checked with git merge-tree); the operator compensating for PowerDNS's DEFAULT soa-edit is the interim step before the operator owns the serial after #201; and the PowerDNS container tests run first in CI. Nits left unapplied: two narrating comments and a duplicated field split.

No findings were applied in this pass, so no commits were added; the head is 0ddc9be.

CI: every check on the head passed, including Chainsaw E2E, the Ubuntu test jobs, alert rule validation, image and bundle publishing, and the CLA check.

Auto-merge is enabled with the merge method (merge commit). The ruleset requires one approving review with code owner review and approval of the last push, so the PR waits for a human approval.

@kevwilliams kevwilliams left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sound. PowerDNS bumps the serial it receives, so writing today's default when the zone already holds a higher serial moves it backwards. keepSOASerialRising reads the held serial from the zone's current state and only raises the desired value when it is lower, leaving it alone otherwise. Five test cases, held-above, held-below, explicit-above, explicit-below, and no-SOA, exercise the real EnsureRecordSet path and would fail without the fix. CI green.

@ecv
ecv merged commit 32aaaef into main Oct 3, 2026
12 checks passed
@ecv
ecv deleted the fix/soa-serial-keep branch October 3, 2026 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants