From 1eff586a40461fd0bdb54dfcfc6ba060096abe8b Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 18:06:15 +0200 Subject: [PATCH] Hold the filter module to replacing the stock unit's flushing stop (hq ADR 0100) --- .../catalogue/foundation_manifests_test.go | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/internal/catalogue/foundation_manifests_test.go b/internal/catalogue/foundation_manifests_test.go index 08886c4..f8f524e 100644 --- a/internal/catalogue/foundation_manifests_test.go +++ b/internal/catalogue/foundation_manifests_test.go @@ -1,6 +1,7 @@ package catalogue import ( + "fmt" "os" "reflect" "strings" @@ -34,12 +35,13 @@ func TestTheStoreAndTheBrokerSayWhatTheMeshGuards(t *testing.T) { func TestTheFilterModuleNeverFlushesTheRuleset(t *testing.T) { m := catalogueManifest(t, "nftables") - var unit map[string]any - var load map[string]any + var unit, stock, load map[string]any for _, r := range m.Resources { switch r["id"] { case "unit": unit = r + case "stock-unit-stop": + stock = r case "load": load = r } @@ -60,7 +62,16 @@ func TestTheFilterModuleNeverFlushesTheRuleset(t *testing.T) { t.Fatalf("the unit does not load the computed rule set and delete only its own table:\n%s", content) } - if !reflect.DeepEqual(load["restart-on"], []any{"filtering", "unit"}) { - t.Fatalf("the filter is not reloaded when its rules or its unit change: %v", load["restart-on"]) + // A node converged before the filter had its own unit still has the stock nftables.service + // enabled, whose stop flushes the whole ruleset: a drop-in makes it delete only the mesh's + // table, and the load is restarted on it so the host reloads units and the drop-in is read. + if stock == nil || stock["path"] != "/etc/systemd/system/nftables.service.d/mesh.conf" || + !strings.HasSuffix(fmt.Sprint(stock["content"]), + "[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n") { + t.Fatalf("the stock unit's stop is not replaced with deleting the mesh's table: %v", stock) + } + if !reflect.DeepEqual(load["restart-on"], []any{"filtering", "unit", "stock-unit-stop"}) { + t.Fatalf("the filter is not reloaded when its rules, its unit or the stock unit's drop-in "+ + "change: %v", load["restart-on"]) } }