health-drain-resume-returns
Purpose
Draining the only answering backend yields a forward-timeout SERVFAIL; resume on that backend (with the sibling held down) restores successful answers. Proves drain/resume round-trip without relying on fail-open alone.
Results appear on the Conduit behavior matrix (one stub peer). Requires a
host conduitctl binary (see interop README).
How it works
- Pool:
live(stub) anddead(unused IP); slow probes so operator controls own applied state for the proof. - Drain
live→ dig gets SERVFAIL (onlydeadremains eligible and times out). - Resume
live, then draindeadso fail-open cannot re-admit a blackhole. - Second dig succeeds on
live. - Checks require SERVFAIL then NOERROR, one peer query overall, one dead timeout attempt, and one live success.
Outcomes
| Outcome | Meaning for operators |
|---|---|
| pass | Drain caused SERVFAIL; resume restored live answers. |
| fail | Unexpected rcodes, peer traffic, or missing drain/resume effect. |
| skip | This peer/profile combination is out of scope. |
| characterized | Not used for this case today. If it appeared, it would mean a documented peer-specific quirk rather than a Conduit regression. |
Matrix: conduit (Conduit behavior)
Suites: full
Oracles: sequence, property, peer-query-count, metrics-delta