diff --git a/internal/catalogue/adoption.go b/internal/catalogue/adoption.go index f38c7ae..c7957c0 100644 --- a/internal/catalogue/adoption.go +++ b/internal/catalogue/adoption.go @@ -207,8 +207,10 @@ func GuardUnitText() string { } // GuardResources are the guard as four resources of the existing kinds: the tool that loads it, -// the table, the unit, and the unit running, restarted when the table changes. Nothing when there -// is nothing to guard: an empty set is not a table nft loads. +// the table, the unit, and the unit running — reloaded when the table changes, so the new table +// replaces the old in one `nft -f` through the unit's ExecReload with no moment unguarded, and +// restarted only when the unit itself changes. Nothing when there is nothing to guard: an empty +// set is not a table nft loads. func GuardResources(ports []int) []map[string]any { if len(ports) == 0 { return nil @@ -220,6 +222,6 @@ func GuardResources(ports []int) []map[string]any { {"id": GuardUnitID(), "type": "file", "path": GuardUnitPath, "content": GuardUnitText(), "mode": "0644"}, {"id": GuardRunningID(), "type": "service", "unit": GuardUnit, "state": "running", - "boot": "enabled", "restart-on": []any{GuardID(), GuardUnitID()}}, + "boot": "enabled", "restart-on": []any{GuardUnitID()}, "reload-on": []any{GuardID()}}, } } diff --git a/internal/catalogue/adoption_test.go b/internal/catalogue/adoption_test.go index b53e956..949288a 100644 --- a/internal/catalogue/adoption_test.go +++ b/internal/catalogue/adoption_test.go @@ -174,8 +174,12 @@ func TestAnAdoptedNodeLoadsNoFilterOfTheMeshs(t *testing.T) { if pkg < 0 || pkg > table { t.Fatalf("nftables is not declared before the guard's table (%d, %d)", pkg, table) } - if !reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardID(), GuardUnitID()}) { - t.Fatalf("the guard is not reloaded when its table changes: %v", got[GuardRunningID()]) + // A changed table is reloaded — one `nft -f`, atomic — never restarted, which would delete the + // table and leave the ports unguarded until it is loaded again. Only a changed unit restarts. + if !reflect.DeepEqual(got[GuardRunningID()]["reload-on"], []any{GuardID()}) || + !reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardUnitID()}) { + t.Fatalf("the guard is not reloaded on its table and restarted on its unit: %v", + got[GuardRunningID()]) } // Nothing of the mesh's own is anybody's to hold. for id, module := range composed.Owner {