Reload the guard on its table rather than restart it, so a change leaves no port unguarded (hq ADR 0103)
This commit is contained in:
@@ -207,8 +207,10 @@ func GuardUnitText() string {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// GuardResources are the guard as four resources of the existing kinds: the tool that loads it,
|
// GuardResources are the guard as four resources of the existing kinds: the tool that loads it,
|
||||||
// the table, the unit, and the unit running, restarted when the table changes. Nothing when there
|
// the table, the unit, and the unit running — reloaded when the table changes, so the new table
|
||||||
// is nothing to guard: an empty set is not a table nft loads.
|
// replaces the old in one `nft -f` through the unit's ExecReload with no moment unguarded, and
|
||||||
|
// restarted only when the unit itself changes. Nothing when there is nothing to guard: an empty
|
||||||
|
// set is not a table nft loads.
|
||||||
func GuardResources(ports []int) []map[string]any {
|
func GuardResources(ports []int) []map[string]any {
|
||||||
if len(ports) == 0 {
|
if len(ports) == 0 {
|
||||||
return nil
|
return nil
|
||||||
@@ -220,6 +222,6 @@ func GuardResources(ports []int) []map[string]any {
|
|||||||
{"id": GuardUnitID(), "type": "file", "path": GuardUnitPath, "content": GuardUnitText(),
|
{"id": GuardUnitID(), "type": "file", "path": GuardUnitPath, "content": GuardUnitText(),
|
||||||
"mode": "0644"},
|
"mode": "0644"},
|
||||||
{"id": GuardRunningID(), "type": "service", "unit": GuardUnit, "state": "running",
|
{"id": GuardRunningID(), "type": "service", "unit": GuardUnit, "state": "running",
|
||||||
"boot": "enabled", "restart-on": []any{GuardID(), GuardUnitID()}},
|
"boot": "enabled", "restart-on": []any{GuardUnitID()}, "reload-on": []any{GuardID()}},
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -174,8 +174,12 @@ func TestAnAdoptedNodeLoadsNoFilterOfTheMeshs(t *testing.T) {
|
|||||||
if pkg < 0 || pkg > table {
|
if pkg < 0 || pkg > table {
|
||||||
t.Fatalf("nftables is not declared before the guard's table (%d, %d)", pkg, table)
|
t.Fatalf("nftables is not declared before the guard's table (%d, %d)", pkg, table)
|
||||||
}
|
}
|
||||||
if !reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardID(), GuardUnitID()}) {
|
// A changed table is reloaded — one `nft -f`, atomic — never restarted, which would delete the
|
||||||
t.Fatalf("the guard is not reloaded when its table changes: %v", got[GuardRunningID()])
|
// table and leave the ports unguarded until it is loaded again. Only a changed unit restarts.
|
||||||
|
if !reflect.DeepEqual(got[GuardRunningID()]["reload-on"], []any{GuardID()}) ||
|
||||||
|
!reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardUnitID()}) {
|
||||||
|
t.Fatalf("the guard is not reloaded on its table and restarted on its unit: %v",
|
||||||
|
got[GuardRunningID()])
|
||||||
}
|
}
|
||||||
// Nothing of the mesh's own is anybody's to hold.
|
// Nothing of the mesh's own is anybody's to hold.
|
||||||
for id, module := range composed.Owner {
|
for id, module := range composed.Owner {
|
||||||
|
|||||||
Reference in New Issue
Block a user