Interop
Published correctness results for DNSConduit against peer DNS software under test. Peer contract cases are split by publisher (alphabetical). Conduit behavior cases (cache path, rules, dataplane runtime) use a single stub peer — see Conduit behavior. No peer is preferred or recommended.
By default, Conduit’s forward path passes peer response shapes through (rcode, answer section, and flags such as AA/TC) so operators see the same backend quirks they would when querying the peer directly. Cases that document those quirks use parity against a direct dig; characterized cells record expected peer-specific shapes. Configuration that rewrites or sanitizes peer answers is covered separately when those knobs are under test.
Matrices
- Conduit behavior — Conduit-focused cases (stub peer)
Publishers
- CZ.NIC — Knot DNS
- ISC — BIND, BIND Resolver
- NLnet Labs — Unbound
- PowerDNS — Authoritative Server, Recursor
- thekelleys — dnsmasq
Last tested 2026-08-06 · No failures; 8 characterized
Outcomes
| Outcome | Meaning |
|---|---|
| pass | Case checks met for this peer/version — the declared contract holds |
| fail | Unexpected mismatch or error — investigate Conduit forwarding or the peer path for this cell |
| skip | Out of scope for this peer role or profile (not a failure) |
| characterized | Documented peer-specific behavior (see the case page), not treated as a Conduit regression |
Each case page explains purpose, how the test runs, and what these outcomes mean for that case.
Running these tests locally
The matrices on this site are from a committed lab run. You can reproduce or explore the same harness on a machine with Docker, Docker Compose, and Python 3 (with PyYAML). GitHub Actions does not execute the Docker suite; CI only checks that committed results stay fresh when harness inputs change.
From a checkout of the DNSConduit repository:
-
Build a Conduit image used as the system under test:
make interop-imageThis builds
conduit:localvia the repoDockerfile. Override withCONDUIT_IMAGE=…if you already have an image tag. -
Run the smoke suite (all peers the smoke cases apply to). Peer images are pulled as needed; the first run can take a while:
make interop-smoke -
Optional — authoritative fixture case (auth peers only):
make interop-auth
Those targets print pass/fail/skip lines; they do not rewrite interop/results/latest.json or regenerate this site. Named cases document purpose, how each test works, and outcome implications.
Useful extras:
| Command | What it does |
|---|---|
make interop-unit |
Fast harness unit tests (no Docker cells) |
make interop-docs |
Rebuild these matrix pages from the committed latest.json |
make interop-refresh |
Rebuild image, re-run smoke + auth, write results and regenerate docs (maintainers) |
Filters (peer, case, profile) and pack layout: see interop/README.md in the repository. Override the image for any run target with make interop-smoke CONDUIT_IMAGE=registry.example/conduit:1.2.3.
Summary
| Outcome | Test | Publisher | Product | Version | Profile |
|---|---|---|---|---|---|
| characterized | dnsmasq-cname-ignored-nonlocal |
thekelleys | dnsmasq | 2.90 | forward-only |
| characterized | pdns-recursor-rd0-refused |
PowerDNS | Recursor | 5.3 | forward-only |
| characterized | pdns-recursor-rd0-refused |
PowerDNS | Recursor | 5.4 | forward-only |
| characterized | recursive-outside-aa-shape |
NLnet Labs | Unbound | 1.21 | forward-only |
| characterized | recursive-outside-aa-shape |
NLnet Labs | Unbound | 1.22 | forward-only |
| characterized | recursive-outside-aa-shape |
PowerDNS | Recursor | 5.3 | forward-only |
| characterized | recursive-outside-aa-shape |
PowerDNS | Recursor | 5.4 | forward-only |
| characterized | stub-aaaa-for-a-only |
thekelleys | dnsmasq | 2.90 | forward-only |
Peer catalog
Peers are software under test. Ordering is publisher (A–Z), product (A–Z), version ascending.
| Publisher | Product | Version | Role | Id |
|---|---|---|---|---|
| CZ.NIC | Knot DNS | 3.4 | auth | cznic-knot-3.4 |
| CZ.NIC | Knot DNS | 3.5 | auth | cznic-knot-3.5 |
| ISC | BIND | 9.18 | auth | isc-bind-9.18 |
| ISC | BIND | 9.20 | auth | isc-bind-9.20 |
| ISC | BIND Resolver | 9.18 | recursive | isc-bind-resolver-9.18 |
| ISC | BIND Resolver | 9.20 | recursive | isc-bind-resolver-9.20 |
| NLnet Labs | Unbound | 1.21 | recursive | nlnetlabs-unbound-1.21 |
| NLnet Labs | Unbound | 1.22 | recursive | nlnetlabs-unbound-1.22 |
| PowerDNS | Authoritative Server | 5.0 | auth | powerdns-auth-5.0 |
| PowerDNS | Authoritative Server | 5.1 | auth | powerdns-auth-5.1 |
| PowerDNS | Recursor | 5.3 | recursive | powerdns-recursor-5.3 |
| PowerDNS | Recursor | 5.4 | recursive | powerdns-recursor-5.4 |
| thekelleys | dnsmasq | 2.90 | stub | thekelleys-dnsmasq-2.90 |