Say in the converge preview that routed traffic is not previewed and is dropped unless declared (hq ADR 0100)

This commit is contained in:
2026-09-22 18:01:04 +02:00
parent 3dc7d0e386
commit ba0f44a36d
2 changed files with 8 additions and 0 deletions
+3
View File
@@ -171,6 +171,9 @@ func TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken(t *testing.T)
"notes\n replacing the found file /etc/notes.conf (original kept at",
"assigns nftables",
"the found firewall (ufw) is disabled, never flushed",
// What it routes is not a listener: said not to be previewed, and to be dropped.
"not previewed: traffic the machine routes that is not a published port",
"the derived filter drops it unless a module declares it",
} {
if !strings.Contains(preview, want) {
t.Errorf("the preview does not say %q:\n%s", want, preview)
+5
View File
@@ -276,6 +276,11 @@ func previewOf(node string, reported inventory.Adoption, derived derivedFilter,
if len(reported.Reachable) == 0 {
b.WriteString(" nothing reported\n")
}
// What the machine routes for others is not a listener and not a published port, so nothing
// above can show it; the derived filter's forward chain drops it all the same.
b.WriteString(" not previewed: traffic the machine routes that is not a published port " +
"(a tunnel, NAT in the found firewall) — the derived filter drops it unless a module " +
"declares it\n")
isTaken := map[string]bool{}
for _, m := range taken {