Hold the filter module to reloading its rules and restarting only on its units (hq ADR 0102)

This commit is contained in:
2026-09-22 19:47:43 +02:00
parent d05a5e87af
commit 379f459498
@@ -70,8 +70,15 @@ func TestTheFilterModuleNeverFlushesTheRuleset(t *testing.T) {
"[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n") {
t.Fatalf("the stock unit's stop is not replaced with deleting the mesh's table: %v", stock)
}
if !reflect.DeepEqual(load["restart-on"], []any{"filtering", "unit", "stock-unit-stop"}) {
t.Fatalf("the filter is not reloaded when its rules, its unit or the stock unit's drop-in "+
"change: %v", load["restart-on"])
// A changed rule set is RELOADED — ExecReload replaces the table in one `nft -f`, so the node
// is never unfiltered — and only the units themselves restart it, which is the one change a
// reload cannot carry.
if !reflect.DeepEqual(load["reload-on"], []any{"filtering"}) {
t.Fatalf("the filter is restarted rather than reloaded when its rules change, leaving the "+
"node unfiltered in between: %v", load)
}
if !reflect.DeepEqual(load["restart-on"], []any{"unit", "stock-unit-stop"}) {
t.Fatalf("the filter is not restarted when its unit or the stock unit's drop-in changes: %v",
load["restart-on"])
}
}