Adoption mode: a node in use is adopted before it is converged (hq ADR 0100–0103) #44

Merged
jschoubben merged 33 commits from feat/adoption-mode into main 2026-09-22 19:01:51 +00:00
Showing only changes of commit 1eff586a40 - Show all commits
@@ -1,6 +1,7 @@
package catalogue
import (
"fmt"
"os"
"reflect"
"strings"
@@ -34,12 +35,13 @@ func TestTheStoreAndTheBrokerSayWhatTheMeshGuards(t *testing.T) {
func TestTheFilterModuleNeverFlushesTheRuleset(t *testing.T) {
m := catalogueManifest(t, "nftables")
var unit map[string]any
var load map[string]any
var unit, stock, load map[string]any
for _, r := range m.Resources {
switch r["id"] {
case "unit":
unit = r
case "stock-unit-stop":
stock = r
case "load":
load = r
}
@@ -60,7 +62,16 @@ func TestTheFilterModuleNeverFlushesTheRuleset(t *testing.T) {
t.Fatalf("the unit does not load the computed rule set and delete only its own table:\n%s",
content)
}
if !reflect.DeepEqual(load["restart-on"], []any{"filtering", "unit"}) {
t.Fatalf("the filter is not reloaded when its rules or its unit change: %v", load["restart-on"])
// A node converged before the filter had its own unit still has the stock nftables.service
// enabled, whose stop flushes the whole ruleset: a drop-in makes it delete only the mesh's
// table, and the load is restarted on it so the host reloads units and the drop-in is read.
if stock == nil || stock["path"] != "/etc/systemd/system/nftables.service.d/mesh.conf" ||
!strings.HasSuffix(fmt.Sprint(stock["content"]),
"[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n") {
t.Fatalf("the stock unit's stop is not replaced with deleting the mesh's table: %v", stock)
}
if !reflect.DeepEqual(load["restart-on"], []any{"filtering", "unit", "stock-unit-stop"}) {
t.Fatalf("the filter is not reloaded when its rules, its unit or the stock unit's drop-in "+
"change: %v", load["restart-on"])
}
}