Exempt only the daemons a fresh machine was measured to run from counting as in use (hq ADR 0101)

This commit is contained in:
2026-09-22 19:57:52 +02:00
parent 7beb752be0
commit 04665d36c8
2 changed files with 28 additions and 10 deletions
+19 -5
View File
@@ -14,16 +14,14 @@ import (
// and listener it counted.
// Lines as `ss -Hltunp` prints them. The ssh, samba, loopback and proxy lines are captured from a
// real machine; the resolver, DHCP and time lines are written in the same shape. What a fresh machine
// actually runs is measured in testdata/fresh-machine-listeners.txt.
// real machine; the resolver and network-manager lines are written in the same shape. What a fresh
// machine actually runs is measured in testdata/fresh-machine-listeners.txt.
const inUseSockets = `tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:* users:(("sshd",pid=1188536,fd=6))
tcp LISTEN 0 128 [::]:22 [::]:* users:(("sshd",pid=1188536,fd=7))
tcp LISTEN 0 32 127.0.0.1:53 0.0.0.0:* users:(("dnsmasq",pid=1189392,fd=7))
tcp LISTEN 0 4096 127.0.0.1:5432 0.0.0.0:* users:(("docker-proxy",pid=1854543,fd=7))
udp UNCONN 0 0 0.0.0.0:5355 0.0.0.0:* users:(("systemd-resolve",pid=301,fd=11))
udp UNCONN 0 0 192.0.2.10%eth0:68 0.0.0.0:* users:(("systemd-network",pid=280,fd=19))
udp UNCONN 0 0 0.0.0.0:68 0.0.0.0:* users:(("dhcpcd",pid=270,fd=9))
udp UNCONN 0 0 0.0.0.0:123 0.0.0.0:* users:(("systemd-timesyn",pid=260,fd=9))
`
const servingSockets = `tcp LISTEN 0 50 0.0.0.0:445 0.0.0.0:* users:(("smbd",pid=1248,fd=29))
@@ -47,7 +45,7 @@ func TestAFreshMachineIsNotInUse(t *testing.T) {
t.Fatal(err)
}
if len(containers) != 0 || len(listeners) != 0 {
t.Errorf("ssh, loopback, name resolution, DHCP and time were counted: %v %v", containers, listeners)
t.Errorf("ssh, loopback and the daemons a fresh machine runs were counted: %v %v", containers, listeners)
}
}
@@ -163,3 +161,19 @@ func TestARerunWithTheFlagOnAConvergedMachineIsRefused(t *testing.T) {
t.Errorf("a converged re-run of a converged machine was refused: %v", err)
}
}
func TestOnlyTheDaemonsTheMeasurementFoundAreQuiet(t *testing.T) {
// novox/hq ADR 0101: the exempt daemons are the ones a fresh machine was measured to run —
// the resolver and the network manager. A time client or a DHCP client listening beyond
// loopback is something somebody put there, and that is a machine in use.
sockets := `udp UNCONN 0 0 0.0.0.0:123 0.0.0.0:* users:(("systemd-timesyn",pid=260,fd=9))
udp UNCONN 0 0 0.0.0.0:68 0.0.0.0:* users:(("dhcpcd",pid=270,fd=9))
`
_, listeners, err := InUse(context.Background(), inUseRunner{ss: sockets}.run, func(string) bool { return false })
if err != nil {
t.Fatal(err)
}
if len(listeners) != 2 {
t.Errorf("counted %d listener(s), want the time client and the DHCP client: %+v", len(listeners), listeners)
}
}