From 9d13b0593b828f5559f342df1945b34af6a582cc Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 2 Oct 2026 14:04:35 +0200 Subject: [PATCH] A filter module's own filter file counts as declared for a mount (hq ADR 0169) The nftables module's runtime mounts the file filtering.into names, to reload the mesh's table; the mount check knew every other declaration of a path and not this one, and the module's first build was refused for it. --- internal/catalogue/manifest.go | 6 ++++++ internal/catalogue/mounts_test.go | 10 ++++++++++ 2 files changed, 16 insertions(+) diff --git a/internal/catalogue/manifest.go b/internal/catalogue/manifest.go index faf1612..5ce6543 100644 --- a/internal/catalogue/manifest.go +++ b/internal/catalogue/manifest.go @@ -1810,6 +1810,12 @@ func (m Manifest) undeclaredMounts() []string { claim(p) } } + // The file a filter module's rule set is written to is declared by `filtering.into`: the mesh + // writes it, the module loads it, and the module's runtime may read it back to reload the + // mesh's own table (novox/hq ADR 0169). + if m.Filtering != nil { + claim(m.Filtering.Into) + } // Under a declared directory is declared: a module that says where its data lives has said so // for what it puts inside. covers := func(path string) bool { diff --git a/internal/catalogue/mounts_test.go b/internal/catalogue/mounts_test.go index 15125cc..c79c7b5 100644 --- a/internal/catalogue/mounts_test.go +++ b/internal/catalogue/mounts_test.go @@ -98,3 +98,13 @@ func TestAMountOfABoundFactIsAccepted(t *testing.T) { t.Fatalf("a mount of the file the mesh writes a binding to was refused: %v", err) } } + +// The file a filter module's rule set is written to is declared by `filtering.into` (novox/hq ADR +// 0169): the module's runtime mounts it to reload the mesh's own table, and nothing else declares it. +func TestAMountOfTheFilterFileIsDeclaredByFilteringInto(t *testing.T) { + _, err := ParseManifest([]byte(`{"module":"nftables","filtering":{"into":"/etc/nftables.conf"},` + + `"resources":[` + strings.Replace(aContainerMounting, "%s", "/etc/nftables.conf", 1) + `]}`)) + if err != nil { + t.Fatalf("a filter module mounting its own filter file was refused: %v", err) + } +} -- 2.54.0