Some time in the last week, icann.org gained a reverse DNS record for its IPv6 address:
$ dig +short aaaa icann.org
2001:500:88:200::7
$ dig +short ptr -x 2001:500:88:200::7
icann.org.
This makes the test intelmq/tests/bots/experts/reverse_dns/test_expert.py::TestReverseDnsExpertBot::test_ipv6_lookup fail, since it expects 2001:500:88:200::7 not to have a PTR record:
|
EXAMPLE_INPUT6 = {"__type": "Event", |
|
"source.ip": "2001:500:88:200::8", # iana.org |
|
"source.reverse_dns": "example.com", |
|
"time.observation": "2015-01-01T00:00:00+00:00", |
|
"destination.ip": "2001:500:88:200::7", # has no reverse record, certtools/intelmq#2394 |
|
} |
|
EXAMPLE_OUTPUT6 = {"__type": "Event", |
|
"source.ip": "2001:500:88:200::8", |
|
"source.reverse_dns": "iana.org", |
|
"destination.ip": "2001:500:88:200::7", |
|
"time.observation": "2015-01-01T00:00:00+00:00", |
|
} |
I assume the test is there to check that if no PTR record exists no spurious
*.reverse_dns field is returned, so should the address be replaced with something out of a
special-purpose address block, e.g.
2001:db8::1 (which is reserved for documentation)? It's not guaranteed not to have a PTR record, but it seems more stable than a publicly routable address.
=================================== FAILURES ===================================
___________________ TestReverseDnsExpertBot.test_ipv6_lookup ___________________
self = <intelmq.tests.bots.experts.reverse_dns.test_expert.TestReverseDnsExpertBot testMethod=test_ipv6_lookup>
def test_ipv6_lookup(self):
self.input_message = EXAMPLE_INPUT6
self.run_bot()
> self.assertMessageEqual(0, EXAMPLE_OUTPUT6)
intelmq/tests/bots/experts/reverse_dns/test_expert.py:75:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
intelmq/lib/test.py:591: in assertMessageEqual
self.assertDictEqual(expected, event_dict)
E AssertionError: {'__type': 'Event', 'source.ip': '2001:500:[80 chars]::7'} != {'source.ip': '2001:500:88:200::8', 'source[120 chars]ent'}
E {'__type': 'Event',
E 'destination.ip': '2001:500:88:200::7',
E + 'destination.reverse_dns': 'icann.org',
E 'source.ip': '2001:500:88:200::8',
E 'source.reverse_dns': 'iana.org'}
------------------------------ Captured log call -------------------------------
INFO test-bot:bot.py:182 ReverseDnsExpertBot initialized with id test-bot and intelmq 3.5.0 and python 3.9.25 (main, Aug 6 2026, 00:00:00) as process 187. Standalone mode: False.
DEBUG test-bot:bot.py:182 Library path: '/builds/intelmq/intelmq/intelmq/lib/bot.py'.
DEBUG test-bot:bot.py:182 Loading runtime configuration from '/opt/intelmq/etc/runtime.yaml'.
DEBUG test-bot:bot.py:182 System configuration: parameter 'description' loaded with value 'Instance of a bot for automated unit tests.'.
DEBUG test-bot:bot.py:182 System configuration: parameter 'group' loaded with value 'Expert'.
DEBUG test-bot:bot.py:182 System configuration: parameter 'module' loaded with value 'intelmq.bots.experts.reverse_dns.expert'.
DEBUG test-bot:bot.py:182 System configuration: parameter 'name' loaded with value 'Test Bot'.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'destination_pipeline_broker' loaded with value 'pythonlist'.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'logging_handler' loaded with value 'stream'.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'logging_path' loaded with value None.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'logging_level' loaded with value 'DEBUG'.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'rate_limit' loaded with value 0.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'retry_delay' loaded with value 0.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'error_retry_delay' loaded with value 0.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'error_max_retries' loaded with value 0.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'redis_cache_host' loaded with value 'localhost'.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'redis_cache_port' loaded with value 6379.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'redis_cache_db' loaded with value 4.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'redis_cache_ttl' loaded with value 10.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'redis_cache_password' loaded with value 'HIDDEN'.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'source_pipeline_broker' loaded with value 'pythonlist'.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'testing' loaded with value True.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'overwrite' loaded with value True.
DEBUG test-bot:bot.py:182 Runtime configuration: parameter 'destination_queues' loaded with value {'_default': 'test-bot-output'}.
DEBUG test-bot:bot.py:182 Environment configuration: parameter 'test_exotic' loaded with value 1.
INFO test-bot:bot.py:185 Bot is starting.
DEBUG test-bot:bot.py:925 Loading Harmonization configuration from '/opt/intelmq/etc/harmonization.conf'.
INFO test-bot:bot.py:633 Loading source pipeline and queue 'test-bot-queue'.
INFO test-bot:bot.py:643 Connected to source queue.
INFO test-bot:bot.py:646 Loading destination pipeline and queues {'_default': 'test-bot-output'}.
INFO test-bot:bot.py:655 Connected to destination queues.
INFO test-bot:bot.py:267 Bot initialization completed.
DEBUG test-bot:bot.py:723 Waiting for incoming message.
DEBUG test-bot:bot.py:758 Received message {'source.ip': '2001:500:88:200::8', 'source.reverse_dns': 'example.com', 'time.observation': '2015-01-01T00:00:00+00:00', 'destination.ip': '2001:500:88:200::7'}.
DEBUG test-bot:bot.py:687 Sending message to path '_default'.
DEBUG test-bot:bot.py:487 Testing environment detected, returning now.
INFO test-bot:bot.py:585 Processed 1 messages since last logging.
DEBUG test-bot:bot.py:664 Disconnected from source pipeline.
DEBUG test-bot:bot.py:668 Disconnected from destination pipeline.
INFO test-bot:bot.py:596 Bot stopped.
Some time in the last week, icann.org gained a reverse DNS record for its IPv6 address:
This makes the test
intelmq/tests/bots/experts/reverse_dns/test_expert.py::TestReverseDnsExpertBot::test_ipv6_lookupfail, since it expects2001:500:88:200::7not to have a PTR record:intelmq/intelmq/tests/bots/experts/reverse_dns/test_expert.py
Lines 24 to 35 in bbe452a
I assume the test is there to check that if no PTR record exists no spurious
*.reverse_dnsfield is returned, so should the address be replaced with something out of a special-purpose address block, e.g.2001:db8::1(which is reserved for documentation)? It's not guaranteed not to have a PTR record, but it seems more stable than a publicly routable address.