Reload the guard on its table rather than restart it, so a change leaves no port unguarded (hq ADR 0103)

This commit is contained in:
2026-09-22 18:27:27 +02:00
parent bfe4991dd7
commit cc47330884
2 changed files with 11 additions and 5 deletions
+5 -3
View File
@@ -207,8 +207,10 @@ func GuardUnitText() string {
} }
// GuardResources are the guard as four resources of the existing kinds: the tool that loads it, // GuardResources are the guard as four resources of the existing kinds: the tool that loads it,
// the table, the unit, and the unit running, restarted when the table changes. Nothing when there // the table, the unit, and the unit running — reloaded when the table changes, so the new table
// is nothing to guard: an empty set is not a table nft loads. // replaces the old in one `nft -f` through the unit's ExecReload with no moment unguarded, and
// restarted only when the unit itself changes. Nothing when there is nothing to guard: an empty
// set is not a table nft loads.
func GuardResources(ports []int) []map[string]any { func GuardResources(ports []int) []map[string]any {
if len(ports) == 0 { if len(ports) == 0 {
return nil return nil
@@ -220,6 +222,6 @@ func GuardResources(ports []int) []map[string]any {
{"id": GuardUnitID(), "type": "file", "path": GuardUnitPath, "content": GuardUnitText(), {"id": GuardUnitID(), "type": "file", "path": GuardUnitPath, "content": GuardUnitText(),
"mode": "0644"}, "mode": "0644"},
{"id": GuardRunningID(), "type": "service", "unit": GuardUnit, "state": "running", {"id": GuardRunningID(), "type": "service", "unit": GuardUnit, "state": "running",
"boot": "enabled", "restart-on": []any{GuardID(), GuardUnitID()}}, "boot": "enabled", "restart-on": []any{GuardUnitID()}, "reload-on": []any{GuardID()}},
} }
} }
+6 -2
View File
@@ -174,8 +174,12 @@ func TestAnAdoptedNodeLoadsNoFilterOfTheMeshs(t *testing.T) {
if pkg < 0 || pkg > table { if pkg < 0 || pkg > table {
t.Fatalf("nftables is not declared before the guard's table (%d, %d)", pkg, table) t.Fatalf("nftables is not declared before the guard's table (%d, %d)", pkg, table)
} }
if !reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardID(), GuardUnitID()}) { // A changed table is reloaded — one `nft -f`, atomic — never restarted, which would delete the
t.Fatalf("the guard is not reloaded when its table changes: %v", got[GuardRunningID()]) // table and leave the ports unguarded until it is loaded again. Only a changed unit restarts.
if !reflect.DeepEqual(got[GuardRunningID()]["reload-on"], []any{GuardID()}) ||
!reflect.DeepEqual(got[GuardRunningID()]["restart-on"], []any{GuardUnitID()}) {
t.Fatalf("the guard is not reloaded on its table and restarted on its unit: %v",
got[GuardRunningID()])
} }
// Nothing of the mesh's own is anybody's to hold. // Nothing of the mesh's own is anybody's to hold.
for id, module := range composed.Owner { for id, module := range composed.Owner {