- _get_unbound_host_overrides: deduplicate by (hostname, domain, ip, rr)
to suppress alias rows that OPNsense returns alongside parent records
- _get_unbound_host_overrides: read ptrrecord field so callers know which
A records have an auto-managed PTR in the reverse zone
- sync_dns_zone: set ptrrecord=1 when creating A/AAAA host overrides so
OPNsense Unbound manages the PTR record internally
- sync_dns_zone: refuse arpa zone names with ValueError — PTR records
must never be written back via the host override API
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>