Reload the guard on its table rather than restart it, so a change leaves no port unguarded (hq ADR 0103)

This commit is contained in:
2026-09-22 18:27:27 +02:00
parent bfe4991dd7
commit cc47330884
2 changed files with 11 additions and 5 deletions
+6 -2
View File
@@ -174,8 +174,12 @@ func TestAnAdoptedNodeLoadsNoFilterOfTheMeshs(t *testing.T) {
if pkg < 0 || pkg > table {
t.Fatalf("nftables is not declared before the guard's table (%d, %d)", pkg, table)
}
if !reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardID(), GuardUnitID()}) {
t.Fatalf("the guard is not reloaded when its table changes: %v", got[GuardRunningID()])
// A changed table is reloaded — one `nft -f`, atomic — never restarted, which would delete the
// table and leave the ports unguarded until it is loaded again. Only a changed unit restarts.
if !reflect.DeepEqual(got[GuardRunningID()]["reload-on"], []any{GuardID()}) ||
!reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardUnitID()}) {
t.Fatalf("the guard is not reloaded on its table and restarted on its unit: %v",
got[GuardRunningID()])
}
// Nothing of the mesh's own is anybody's to hold.
for id, module := range composed.Owner {