diff --git a/internal/catalogue/foundation_manifests_test.go b/internal/catalogue/foundation_manifests_test.go index f8f524e..44f95d8 100644 --- a/internal/catalogue/foundation_manifests_test.go +++ b/internal/catalogue/foundation_manifests_test.go @@ -70,8 +70,15 @@ func TestTheFilterModuleNeverFlushesTheRuleset(t *testing.T) { "[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n") { t.Fatalf("the stock unit's stop is not replaced with deleting the mesh's table: %v", stock) } - if !reflect.DeepEqual(load["restart-on"], []any{"filtering", "unit", "stock-unit-stop"}) { - t.Fatalf("the filter is not reloaded when its rules, its unit or the stock unit's drop-in "+ - "change: %v", load["restart-on"]) + // A changed rule set is RELOADED — ExecReload replaces the table in one `nft -f`, so the node + // is never unfiltered — and only the units themselves restart it, which is the one change a + // reload cannot carry. + if !reflect.DeepEqual(load["reload-on"], []any{"filtering"}) { + t.Fatalf("the filter is restarted rather than reloaded when its rules change, leaving the "+ + "node unfiltered in between: %v", load) + } + if !reflect.DeepEqual(load["restart-on"], []any{"unit", "stock-unit-stop"}) { + t.Fatalf("the filter is not restarted when its unit or the stock unit's drop-in changes: %v", + load["restart-on"]) } }