diff --git a/internal/bootstrap/inuse.go b/internal/bootstrap/inuse.go index 023d322..c3cf613 100644 --- a/internal/bootstrap/inuse.go +++ b/internal/bootstrap/inuse.go @@ -12,14 +12,18 @@ import ( ) // quiet are the processes every fresh machine runs that serve nobody: name resolution (whose -// link-local resolver listens on TCP as well as UDP, on every address), address configuration and -// time. ss names a process by its first fifteen characters, so both spellings are here. Measured -// on a freshly installed lab machine (testdata/fresh-machine-listeners.txt): these and nothing else. +// link-local resolver listens on TCP as well as UDP, on every address) and the network manager's +// address configuration. ss names a process by its first fifteen characters, so both spellings are +// here. +// +// **Only what the measurement found** (novox/hq ADR 0101): these two hold every listener on a +// freshly installed lab machine (testdata/fresh-machine-listeners.txt) and nothing else does. A +// daemon joins this list with a measurement of a fresh machine that holds it, never by guess — a +// time client or an address-configuration client listening on a machine that does not run one as +// standard is something somebody installed, and that is a machine in use. var quiet = map[string]bool{ "systemd-resolved": true, "systemd-resolve": true, "systemd-networkd": true, "systemd-network": true, - "systemd-timesyncd": true, "systemd-timesyn": true, - "dhcpcd": true, } // InUse says what makes this machine a machine in use (novox/hq ADR 0100): every running container diff --git a/internal/bootstrap/inuse_test.go b/internal/bootstrap/inuse_test.go index 137ceef..2cc889d 100644 --- a/internal/bootstrap/inuse_test.go +++ b/internal/bootstrap/inuse_test.go @@ -14,16 +14,14 @@ import ( // and listener it counted. // Lines as `ss -Hltunp` prints them. The ssh, samba, loopback and proxy lines are captured from a -// real machine; the resolver, DHCP and time lines are written in the same shape. What a fresh machine -// actually runs is measured in testdata/fresh-machine-listeners.txt. +// real machine; the resolver and network-manager lines are written in the same shape. What a fresh +// machine actually runs is measured in testdata/fresh-machine-listeners.txt. const inUseSockets = `tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:* users:(("sshd",pid=1188536,fd=6)) tcp LISTEN 0 128 [::]:22 [::]:* users:(("sshd",pid=1188536,fd=7)) tcp LISTEN 0 32 127.0.0.1:53 0.0.0.0:* users:(("dnsmasq",pid=1189392,fd=7)) tcp LISTEN 0 4096 127.0.0.1:5432 0.0.0.0:* users:(("docker-proxy",pid=1854543,fd=7)) udp UNCONN 0 0 0.0.0.0:5355 0.0.0.0:* users:(("systemd-resolve",pid=301,fd=11)) udp UNCONN 0 0 192.0.2.10%eth0:68 0.0.0.0:* users:(("systemd-network",pid=280,fd=19)) -udp UNCONN 0 0 0.0.0.0:68 0.0.0.0:* users:(("dhcpcd",pid=270,fd=9)) -udp UNCONN 0 0 0.0.0.0:123 0.0.0.0:* users:(("systemd-timesyn",pid=260,fd=9)) ` const servingSockets = `tcp LISTEN 0 50 0.0.0.0:445 0.0.0.0:* users:(("smbd",pid=1248,fd=29)) @@ -47,7 +45,7 @@ func TestAFreshMachineIsNotInUse(t *testing.T) { t.Fatal(err) } if len(containers) != 0 || len(listeners) != 0 { - t.Errorf("ssh, loopback, name resolution, DHCP and time were counted: %v %v", containers, listeners) + t.Errorf("ssh, loopback and the daemons a fresh machine runs were counted: %v %v", containers, listeners) } } @@ -163,3 +161,19 @@ func TestARerunWithTheFlagOnAConvergedMachineIsRefused(t *testing.T) { t.Errorf("a converged re-run of a converged machine was refused: %v", err) } } + +func TestOnlyTheDaemonsTheMeasurementFoundAreQuiet(t *testing.T) { + // novox/hq ADR 0101: the exempt daemons are the ones a fresh machine was measured to run — + // the resolver and the network manager. A time client or a DHCP client listening beyond + // loopback is something somebody put there, and that is a machine in use. + sockets := `udp UNCONN 0 0 0.0.0.0:123 0.0.0.0:* users:(("systemd-timesyn",pid=260,fd=9)) +udp UNCONN 0 0 0.0.0.0:68 0.0.0.0:* users:(("dhcpcd",pid=270,fd=9)) +` + _, listeners, err := InUse(context.Background(), inUseRunner{ss: sockets}.run, func(string) bool { return false }) + if err != nil { + t.Fatal(err) + } + if len(listeners) != 2 { + t.Errorf("counted %d listener(s), want the time client and the DHCP client: %+v", len(listeners), listeners) + } +}