diff --git a/AGENTS.md b/AGENTS.md index 7247db0..4f46d58 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -51,10 +51,14 @@ Live CDP proof (needs that browser and network, skipped otherwise): `SMOKE_BROWSER_WS_URL=ws://: go test -run 'TestSmokeKagane|TestSmokeComix' ./internal/latest` — fetches a real kagane and comix cover and chapter list. A red run means the challenge is not clearing from this IP, which is a live fact to re-check, not necessarily a defect. -Note for this dev machine: comix.to is DNS-hijacked to an ISP block page here -(`comix.to` CNAMEs to `aduankonten.id`, so Chrome fails `ERR_CERT_COMMON_NAME_INVALID`). -Run the browser container with `--add-host comix.to: --add-host static.comix.to:` -resolved over DoH to get a real reading. +A red `TestSmokeComix` reporting `ERR_CERT_COMMON_NAME_INVALID` is not the +challenge: it means the resolver the browser container uses hijacks `comix.to`. +Observed 2026-08-16 on one Indonesian ISP, which CNAMEs it to a block page +(`aduankonten.id`). Check with `docker exec getent hosts comix.to`, +and if it is hijacked, run the container with +`--add-host comix.to: --add-host static.comix.to:` from a DoH lookup +(`curl -H 'accept: application/dns-json' 'https://1.1.1.1/dns-query?name=comix.to&type=A'`). +Machine-local, so don't put those hosts in `chrome/docker-compose.yml`. Smoke test: `curl` endpoints with `Authorization: Bearer `; confirm `OPTIONS` preflight return CORS headers and `/healthz` return 200.