Declare nftables before the guard's table, so a node joining adopted without nft can load it (hq ADR 0103)

This commit is contained in:
2026-09-22 17:59:32 +02:00
parent a2dfaaf4d1
commit ade6b2bfb6
2 changed files with 31 additions and 7 deletions
+17
View File
@@ -157,6 +157,23 @@ func TestAnAdoptedNodeLoadsNoFilterOfTheMeshs(t *testing.T) {
t.Fatalf("the guard does not guard the store, the broker and its management port:\n%s",
guard["content"])
}
// The tool that loads it comes first, and the table after it: a node joining adopted has no
// filter module and may have no nft.
pkg, table := -1, -1
for i, r := range composed.Resources {
switch r["id"] {
case GuardPackageID():
pkg = i
if r["type"] != "package" || r["package"] != "nftables" {
t.Fatalf("the guard's package is %v", r)
}
case GuardID():
table = i
}
}
if pkg < 0 || pkg > table {
t.Fatalf("nftables is not declared before the guard's table (%d, %d)", pkg, table)
}
if !reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardID(), GuardUnitID()}) {
t.Fatalf("the guard is not reloaded when its table changes: %v", got[GuardRunningID()])
}