Class: GitHubPages::HealthCheck::Domain
- Defined in:
- lib/github-pages-health-check/domain.rb
Constant Summary collapse
- LEGACY_IP_ADDRESSES =
[ # Legacy GitHub Datacenter "207.97.227.245", "204.232.175.78", # Aug. 2016 Fastly datacenter deprecation "199.27.73.133", "199.27.76.133", # Feb. 2017 Fastly datacenter deprecation "103.245.222.133", "103.245.223.133", "103.245.224.133", "104.156.81.133", "104.156.82.133", "104.156.83.133", "104.156.85.133", "104.156.87.133", "104.156.88.133", "104.156.89.133", "104.156.90.133", "104.156.91.133", "104.156.92.133", "104.156.93.133", "104.156.94.133", "104.156.95.133", "104.37.95.133", "157.52.64.133", "157.52.66.133", "157.52.67.133", "157.52.68.133", "157.52.69.133", "157.52.96.133", "172.111.64.133", "172.111.96.133", "185.31.16.133", "185.31.17.133", "185.31.18.133", "185.31.19.133", "199.27.74.133", "199.27.75.133", "199.27.76.133", "199.27.78.133", "199.27.79.133", "23.235.33.133", "23.235.37.133", "23.235.39.133", "23.235.40.133", "23.235.41.133", "23.235.43.133", "23.235.44.133", "23.235.45.133", "23.235.46.133", "23.235.47.133", "23.235.47.133", "43.249.72.133", "43.249.73.133", "43.249.74.133", "43.249.75.133", # 2018 Move to GitHub assigned IP space "192.30.252.153", "192.30.252.154" ].freeze
- CURRENT_IP_ADDRESSES =
%w( 185.199.108.153 185.199.109.153 185.199.110.153 185.199.111.153 ).freeze
- CURRENT_IPV6_ADDRESSES =
%w( 2606:50c0:8000::153 2606:50c0:8001::153 2606:50c0:8002::153 2606:50c0:8003::153 ).freeze
- CURRENT_IP_ADDRESSES_ALL =
(CURRENT_IP_ADDRESSES + CURRENT_IPV6_ADDRESSES).freeze
- HASH_METHODS =
%i[ host uri nameservers dns_resolves? proxied? cloudflare_ip? fastly_ip? old_ip_address? a_record? aaaa_record? a_record_present? aaaa_record_present? cname_record? mx_records_present? valid_domain? apex_domain? should_be_a_record? cname_to_github_user_domain? cname_to_domain_to_pages? cname_to_pages_dot_github_dot_com? cname_to_fastly? pointed_to_github_pages_ip? non_github_pages_ip_present? pages_domain? served_by_pages? valid? reason valid_domain? https? enforces_https? https_error https_eligible? caa_error dns_zone_soa? dns_zone_ns? ].freeze
- REQUESTED_RECORD_TYPES =
[ Dnsruby::Types::A, Dnsruby::Types::AAAA, Dnsruby::Types::CNAME, Dnsruby::Types::MX, Dnsruby::Types::NS, Dnsruby::Types::SOA ].freeze
Instance Attribute Summary collapse
-
#host ⇒ Object
readonly
Returns the value of attribute host.
-
#nameservers ⇒ Object
readonly
Returns the value of attribute nameservers.
-
#resolver ⇒ Object
readonly
Returns the value of attribute resolver.
Class Method Summary collapse
Instance Method Summary collapse
-
#a_record? ⇒ Boolean
Is this domain’s first response an A record?.
-
#a_record_present? ⇒ Boolean
Does this domain has an A record setup (not necessarily as the first record)?.
-
#aaaa_record? ⇒ Boolean
Is this domain’s first response an AAAA record?.
-
#aaaa_record_present? ⇒ Boolean
Does this domain has an AAAA record setup (not necessarily as the first record)?.
-
#apex_domain? ⇒ Boolean
Is this domain an apex domain, meaning a CNAME would be inappropriate.
-
#caa_error ⇒ Object
Any errors querying CAA records.
-
#check! ⇒ Object
Runs all checks, raises an error if invalid rubocop:disable Metrics/AbcSize.
-
#cloudflare_ip? ⇒ Boolean
Does the domain resolve to a CloudFlare-owned IP.
-
#cname ⇒ Object
The domain to which this domain’s CNAME resolves Returns nil if the domain is not a CNAME.
-
#cname_record? ⇒ Boolean
(also: #cname?)
Is this domain’s first response a CNAME record?.
-
#cname_to_domain_to_pages? ⇒ Boolean
Check if the CNAME points to a Domain that points to pages e.g.
-
#cname_to_fastly? ⇒ Boolean
Is the given domain CNAME’d directly to our Fastly account?.
-
#cname_to_github_user_domain? ⇒ Boolean
Is the domain’s first response a CNAME to a pages domain?.
-
#cname_to_pages_dot_github_dot_com? ⇒ Boolean
Is the given domain a CNAME to pages.github.(io|com) instead of being CNAME’d to the user’s subdomain?.
-
#deprecated_ip? ⇒ Boolean
rubocop:enable Metrics/AbcSize.
-
#dns ⇒ Object
Returns an array of DNS answers.
-
#dns? ⇒ Boolean
(also: #dns_resolves?)
Are we even able to get the DNS record?.
-
#dns_zone_ns? ⇒ Boolean
Does the domain have associated NS records?.
-
#dns_zone_soa? ⇒ Boolean
Does the domain have an associated SOA record?.
-
#enforces_https? ⇒ Boolean
Does this domain redirect HTTP requests to HTTPS?.
-
#fastly? ⇒ Boolean
Is the host our Fastly CNAME?.
-
#fastly_ip? ⇒ Boolean
Does the domain resolve to a Fastly-owned IP.
-
#github_domain? ⇒ Boolean
Is this domain owned by GitHub?.
-
#https? ⇒ Boolean
Does this domain respond to HTTPS requests with a valid cert?.
-
#https_eligible? ⇒ Boolean
Can an HTTPS certificate be issued for this domain?.
-
#https_error ⇒ Object
The response code of the HTTPS request, if it failed.
-
#initialize(host, nameservers: :default) ⇒ Domain
constructor
A new instance of Domain.
- #invalid_a_record? ⇒ Boolean
- #invalid_aaaa_record? ⇒ Boolean
- #invalid_cname? ⇒ Boolean
- #mx_records_present? ⇒ Boolean
-
#non_github_pages_ip_present? ⇒ Boolean
Are any of the domain’s A or AAAA records pointing elsewhere?.
-
#old_ip_address? ⇒ Boolean
Does this domain have any A record that points to the legacy IPs?.
-
#pages_domain? ⇒ Boolean
Is the host a *.github.(io|com) domain?.
-
#pages_dot_github_dot_com? ⇒ Boolean
Is the host pages.github.com or pages.github.io?.
-
#pages_io_domain? ⇒ Boolean
Is the host a *.github.io domain?.
-
#pointed_to_github_pages_ip? ⇒ Boolean
Is the domain’s first response an A or AAAA record to a valid GitHub Pages IP?.
-
#proxied? ⇒ Boolean
Does this non-GitHub-pages domain proxy a GitHub Pages site?.
- #served_by_pages? ⇒ Boolean
-
#should_be_a_record? ⇒ Boolean
Should the domain use an A record?.
- #should_be_cname_record? ⇒ Boolean
- #uri(overrides = {}) ⇒ Object
-
#valid_domain? ⇒ Boolean
Is this a valid domain that PublicSuffix recognizes? Used as an escape hatch to prevent false positives on DNS checks.
-
#www_cname(cname) ⇒ Object
Check if we have a ‘www.’ CNAME that matches the domain.
Methods inherited from Checkable
#reason, #to_hash, #to_json, #to_s, #to_s_pretty, #valid?
Constructor Details
#initialize(host, nameservers: :default) ⇒ Domain
Returns a new instance of Domain.
105 106 107 108 109 110 111 112 113 114 |
# File 'lib/github-pages-health-check/domain.rb', line 105 def initialize(host, nameservers: :default) unless host.is_a? String raise ArgumentError, "Expected string, got #{host.class}" end @host = normalize_host(host) @nameservers = nameservers @resolver = GitHubPages::HealthCheck::Resolver.new(self.host, :nameservers => nameservers) end |
Instance Attribute Details
#host ⇒ Object (readonly)
Returns the value of attribute host.
6 7 8 |
# File 'lib/github-pages-health-check/domain.rb', line 6 def host @host end |
#nameservers ⇒ Object (readonly)
Returns the value of attribute nameservers.
6 7 8 |
# File 'lib/github-pages-health-check/domain.rb', line 6 def nameservers @nameservers end |
#resolver ⇒ Object (readonly)
Returns the value of attribute resolver.
6 7 8 |
# File 'lib/github-pages-health-check/domain.rb', line 6 def resolver @resolver end |
Class Method Details
.redundant(host) ⇒ Object
101 102 103 |
# File 'lib/github-pages-health-check/domain.rb', line 101 def self.redundant(host) GitHubPages::HealthCheck::RedundantCheck.new(host).check end |
Instance Method Details
#a_record? ⇒ Boolean
Is this domain’s first response an A record?
367 368 369 370 371 372 |
# File 'lib/github-pages-health-check/domain.rb', line 367 def a_record? return @is_a_record if defined?(@is_a_record) return unless dns? @is_a_record = Dnsruby::Types::A == dns.first.type end |
#a_record_present? ⇒ Boolean
Does this domain has an A record setup (not necessarily as the first record)?
383 384 385 386 387 |
# File 'lib/github-pages-health-check/domain.rb', line 383 def a_record_present? return unless dns? dns.any? { |answer| answer.type == Dnsruby::Types::A && answer.name.to_s == host } end |
#aaaa_record? ⇒ Boolean
Is this domain’s first response an AAAA record?
375 376 377 378 379 380 |
# File 'lib/github-pages-health-check/domain.rb', line 375 def aaaa_record? return @is_aaaa_record if defined?(@is_aaaa_record) return unless dns? @is_aaaa_record = Dnsruby::Types::AAAA == dns.first.type end |
#aaaa_record_present? ⇒ Boolean
Does this domain has an AAAA record setup (not necessarily as the first record)?
390 391 392 393 394 |
# File 'lib/github-pages-health-check/domain.rb', line 390 def aaaa_record_present? return unless dns? dns.any? { |answer| answer.type == Dnsruby::Types::AAAA && answer.name.to_s == host } end |
#apex_domain? ⇒ Boolean
Is this domain an apex domain, meaning a CNAME would be inappropriate
174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 |
# File 'lib/github-pages-health-check/domain.rb', line 174 def apex_domain? return @apex_domain if defined?(@apex_domain) return false unless valid_domain? return true if dns_zone_soa? && dns_zone_ns? # PublicSuffix.domain pulls out the apex-level domain name. # E.g. PublicSuffix.domain("techblog.netflix.com") # => "netflix.com" # It's aware of multi-step top-level domain names: # E.g. PublicSuffix.domain("blog.digital.gov.uk") # => "digital.gov.uk" # For apex-level domain names, DNS providers do not support CNAME records. unicode_host = Addressable::IDNA.to_unicode(host) PublicSuffix.domain(unicode_host, :default_rule => nil, :ignore_private => true) == unicode_host end |
#caa_error ⇒ Object
Any errors querying CAA records
482 483 484 485 486 |
# File 'lib/github-pages-health-check/domain.rb', line 482 def caa_error return nil unless caa&.errored? caa.error.class.name end |
#check! ⇒ Object
Runs all checks, raises an error if invalid rubocop:disable Metrics/AbcSize
118 119 120 121 122 123 124 125 126 127 128 129 |
# File 'lib/github-pages-health-check/domain.rb', line 118 def check! raise Errors::InvalidDomainError.new :domain => self unless valid_domain? raise Errors::InvalidDNSError.new :domain => self unless dns_resolves? raise Errors::DeprecatedIPError.new :domain => self if deprecated_ip? return true if proxied? raise Errors::InvalidARecordError.new :domain => self if invalid_a_record? raise Errors::InvalidCNAMEError.new :domain => self if invalid_cname? raise Errors::InvalidAAAARecordError.new :domain => self if invalid_aaaa_record? raise Errors::NotServedByPagesError.new :domain => self unless served_by_pages? true end |
#cloudflare_ip? ⇒ Boolean
Does the domain resolve to a CloudFlare-owned IP
295 296 297 |
# File 'lib/github-pages-health-check/domain.rb', line 295 def cloudflare_ip? cdn_ip?(CloudFlare) end |
#cname ⇒ Object
The domain to which this domain’s CNAME resolves Returns nil if the domain is not a CNAME
407 408 409 410 411 412 413 414 415 |
# File 'lib/github-pages-health-check/domain.rb', line 407 def cname return unless dns? cnames = dns.take_while { |answer| answer.type == Dnsruby::Types::CNAME } return if cnames.empty? www_cname(cnames.last) @cname ||= Domain.new(cnames.last.cname.to_s) end |
#cname_record? ⇒ Boolean Also known as: cname?
Is this domain’s first response a CNAME record?
397 398 399 400 401 402 |
# File 'lib/github-pages-health-check/domain.rb', line 397 def cname_record? return unless dns? return false unless cname cname.valid_domain? end |
#cname_to_domain_to_pages? ⇒ Boolean
Check if the CNAME points to a Domain that points to pages e.g. CNAME -> Domain -> Pages
248 249 250 251 252 253 254 |
# File 'lib/github-pages-health-check/domain.rb', line 248 def cname_to_domain_to_pages? a_record_to_pages = dns.select { |d| d.type == Dnsruby::Types::A && d.name.to_s == host }.first return false unless a_record_to_pages && cname? && !cname_to_pages_dot_github_dot_com? && @www_cname CURRENT_IP_ADDRESSES.include?(a_record_to_pages.address.to_s.downcase) end |
#cname_to_fastly? ⇒ Boolean
Is the given domain CNAME’d directly to our Fastly account?
265 266 267 |
# File 'lib/github-pages-health-check/domain.rb', line 265 def cname_to_fastly? cname? && !pages_domain? && cname.fastly? end |
#cname_to_github_user_domain? ⇒ Boolean
Is the domain’s first response a CNAME to a pages domain?
242 243 244 |
# File 'lib/github-pages-health-check/domain.rb', line 242 def cname_to_github_user_domain? cname? && !cname_to_pages_dot_github_dot_com? && cname.pages_domain? end |
#cname_to_pages_dot_github_dot_com? ⇒ Boolean
Is the given domain a CNAME to pages.github.(io|com) instead of being CNAME’d to the user’s subdomain?
domain - the domain to check, generally the target of a cname
260 261 262 |
# File 'lib/github-pages-health-check/domain.rb', line 260 def cname_to_pages_dot_github_dot_com? cname? && cname.pages_dot_github_dot_com? end |
#deprecated_ip? ⇒ Boolean
rubocop:enable Metrics/AbcSize
132 133 134 135 136 |
# File 'lib/github-pages-health-check/domain.rb', line 132 def deprecated_ip? return @deprecated_ip if defined? @deprecated_ip @deprecated_ip = (valid_domain? && a_record? && old_ip_address?) end |
#dns ⇒ Object
Returns an array of DNS answers
334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 |
# File 'lib/github-pages-health-check/domain.rb', line 334 def dns return @dns if defined? @dns return unless valid_domain? @dns = Timeout.timeout(TIMEOUT) do GitHubPages::HealthCheck.without_warnings do next if host.nil? REQUESTED_RECORD_TYPES .map { |type| resolver.query(type) } .flatten.uniq end end rescue StandardError @dns = nil end |
#dns? ⇒ Boolean Also known as: dns_resolves?
Are we even able to get the DNS record?
352 353 354 |
# File 'lib/github-pages-health-check/domain.rb', line 352 def dns? !(dns.nil? || dns.empty?) end |
#dns_zone_ns? ⇒ Boolean
Does the domain have associated NS records?
207 208 209 210 211 212 213 214 |
# File 'lib/github-pages-health-check/domain.rb', line 207 def dns_zone_ns? return @ns_records if defined?(@ns_records) return false unless dns? @ns_records = dns.any? do |answer| answer.type == Dnsruby::Types::NS && answer.name.to_s == host end end |
#dns_zone_soa? ⇒ Boolean
Does the domain have an associated SOA record?
195 196 197 198 199 200 201 202 |
# File 'lib/github-pages-health-check/domain.rb', line 195 def dns_zone_soa? return @soa_records if defined?(@soa_records) return false unless dns? @soa_records = dns.any? do |answer| answer.type == Dnsruby::Types::SOA && answer.name.to_s == host end end |
#enforces_https? ⇒ Boolean
Does this domain redirect HTTP requests to HTTPS?
459 460 461 462 463 464 |
# File 'lib/github-pages-health-check/domain.rb', line 459 def enforces_https? return false unless https? && http_response.headers["Location"] redirect = Addressable::URI.parse(http_response.headers["Location"]) redirect.scheme == "https" && redirect.host == host end |
#fastly? ⇒ Boolean
Is the host our Fastly CNAME?
290 291 292 |
# File 'lib/github-pages-health-check/domain.rb', line 290 def fastly? !!host.match(/\A#{Regexp.union(Fastly::HOSTNAMES)}\z/i) end |
#fastly_ip? ⇒ Boolean
Does the domain resolve to a Fastly-owned IP
300 301 302 |
# File 'lib/github-pages-health-check/domain.rb', line 300 def fastly_ip? cdn_ip?(Fastly) end |
#github_domain? ⇒ Boolean
Is this domain owned by GitHub?
285 286 287 |
# File 'lib/github-pages-health-check/domain.rb', line 285 def github_domain? host.downcase.eql?("github.com") || host.downcase.end_with?(".github.com") end |
#https? ⇒ Boolean
Does this domain respond to HTTPS requests with a valid cert?
448 449 450 |
# File 'lib/github-pages-health-check/domain.rb', line 448 def https? https_response.return_code == :ok end |
#https_eligible? ⇒ Boolean
Can an HTTPS certificate be issued for this domain?
467 468 469 470 471 472 473 474 475 476 477 478 479 |
# File 'lib/github-pages-health-check/domain.rb', line 467 def https_eligible? # Can't have any IP's which aren't GitHub's present. return false if non_github_pages_ip_present? # Can't have underscores in the domain name (Let's Encrypt does not allow it) return false if host.include?("_") # Must be a CNAME or point to our IPs. return true if cname_to_github_user_domain? || cname_to_domain_to_pages? # Check CAA records for the full domain and its parent domain. pointed_to_github_pages_ip? && caa.lets_encrypt_allowed? end |
#https_error ⇒ Object
The response code of the HTTPS request, if it failed. Useful for diagnosing cert errors
454 455 456 |
# File 'lib/github-pages-health-check/domain.rb', line 454 def https_error https_response.return_code unless https? end |
#invalid_a_record? ⇒ Boolean
144 145 146 147 148 |
# File 'lib/github-pages-health-check/domain.rb', line 144 def invalid_a_record? return @invalid_a_record if defined? @invalid_a_record @invalid_a_record = (valid_domain? && a_record_present? && !should_be_a_record?) end |
#invalid_aaaa_record? ⇒ Boolean
138 139 140 141 142 |
# File 'lib/github-pages-health-check/domain.rb', line 138 def invalid_aaaa_record? return @invalid_aaaa_record if defined? @invalid_aaaa_record @invalid_aaaa_record = (valid_domain? && aaaa_record_present? && !should_be_a_record?) end |
#invalid_cname? ⇒ Boolean
150 151 152 153 154 155 156 157 158 159 160 |
# File 'lib/github-pages-health-check/domain.rb', line 150 def invalid_cname? return @invalid_cname if defined? @invalid_cname @invalid_cname = begin return false unless valid_domain? return false if github_domain? || apex_domain? return true if cname_to_pages_dot_github_dot_com? || cname_to_fastly? !cname_to_github_user_domain? && should_be_cname_record? end end |
#mx_records_present? ⇒ Boolean
423 424 425 426 427 |
# File 'lib/github-pages-health-check/domain.rb', line 423 def mx_records_present? return unless dns? dns.any? { |answer| answer.type == Dnsruby::Types::MX } end |
#non_github_pages_ip_present? ⇒ Boolean
Are any of the domain’s A or AAAA records pointing elsewhere?
233 234 235 236 237 238 239 |
# File 'lib/github-pages-health-check/domain.rb', line 233 def non_github_pages_ip_present? return unless dns? dns .select { |a| Dnsruby::Types::A == a.type || Dnsruby::Types::AAAA == a.type } .any? { |a| !github_pages_ip?(a.address.to_s) } end |
#old_ip_address? ⇒ Boolean
Does this domain have any A record that points to the legacy IPs?
358 359 360 361 362 363 364 |
# File 'lib/github-pages-health-check/domain.rb', line 358 def old_ip_address? return unless dns? dns.any? do |answer| answer.type == Dnsruby::Types::A && legacy_ip?(answer.address.to_s) end end |
#pages_domain? ⇒ Boolean
Is the host a *.github.(io|com) domain?
275 276 277 |
# File 'lib/github-pages-health-check/domain.rb', line 275 def pages_domain? !!host.match(/\A[\w-]+\.github\.(io|com)\.?\z/i) end |
#pages_dot_github_dot_com? ⇒ Boolean
Is the host pages.github.com or pages.github.io?
280 281 282 |
# File 'lib/github-pages-health-check/domain.rb', line 280 def pages_dot_github_dot_com? !!host.match(/\Apages\.github\.(io|com)\.?\z/i) end |
#pages_io_domain? ⇒ Boolean
Is the host a *.github.io domain?
270 271 272 |
# File 'lib/github-pages-health-check/domain.rb', line 270 def pages_io_domain? !!host.match(/\A[\w-]+\.github\.(io)\.?\z/i) end |
#pointed_to_github_pages_ip? ⇒ Boolean
Is the domain’s first response an A or AAAA record to a valid GitHub Pages IP?
226 227 228 229 230 |
# File 'lib/github-pages-health-check/domain.rb', line 226 def pointed_to_github_pages_ip? return false unless address_record? CURRENT_IP_ADDRESSES_ALL.include?(dns.first.address.to_s.downcase) end |
#proxied? ⇒ Boolean
Does this non-GitHub-pages domain proxy a GitHub Pages site?
This can be:
1. A Cloudflare-owned IP address
2. A site that returns GitHub.com server headers, but
isn't CNAME'd to a GitHub domain
3. A site that returns GitHub.com server headers, but
isn't CNAME'd to a GitHub IP
312 313 314 315 316 317 318 319 320 321 322 |
# File 'lib/github-pages-health-check/domain.rb', line 312 def proxied? return unless dns? return true if cloudflare_ip? return false if pointed_to_github_pages_ip? return false if cname_to_github_user_domain? return false if cname_to_domain_to_pages? return false if cname_to_pages_dot_github_dot_com? return false if cname_to_fastly? || fastly_ip? served_by_pages? end |
#served_by_pages? ⇒ Boolean
429 430 431 432 433 434 435 436 437 438 439 |
# File 'lib/github-pages-health-check/domain.rb', line 429 def served_by_pages? return @served_by_pages if defined? @served_by_pages return unless dns_resolves? @served_by_pages = begin return true if response.headers["Server"] == "GitHub.com" # Typhoeus mangles the case of the header, compare insensitively response.headers.any? { |k, _v| k.downcase == "x-github-request-id" } end end |
#should_be_a_record? ⇒ Boolean
Should the domain use an A record?
217 218 219 |
# File 'lib/github-pages-health-check/domain.rb', line 217 def should_be_a_record? !pages_io_domain? && (apex_domain? || mx_records_present?) end |
#should_be_cname_record? ⇒ Boolean
221 222 223 |
# File 'lib/github-pages-health-check/domain.rb', line 221 def should_be_cname_record? !should_be_a_record? end |
#uri(overrides = {}) ⇒ Object
441 442 443 444 445 |
# File 'lib/github-pages-health-check/domain.rb', line 441 def uri(overrides = {}) = { :host => host, :scheme => scheme, :path => "/" } = .merge(overrides) Addressable::URI.new().normalize.to_s end |
#valid_domain? ⇒ Boolean
Is this a valid domain that PublicSuffix recognizes? Used as an escape hatch to prevent false positives on DNS checks
164 165 166 167 168 169 170 171 |
# File 'lib/github-pages-health-check/domain.rb', line 164 def valid_domain? return @valid if defined? @valid unicode_host = Addressable::IDNA.to_unicode(host) @valid = PublicSuffix.valid?(unicode_host, :default_rule => nil, :ignore_private => true) end |
#www_cname(cname) ⇒ Object
Check if we have a ‘www.’ CNAME that matches the domain
418 419 420 421 |
# File 'lib/github-pages-health-check/domain.rb', line 418 def www_cname(cname) @www_cname ||= cname.name.to_s.start_with?("www.") && cname.name.to_s.end_with?(cname.domainname.to_s) end |