Delete a forwarded opening the way ufw accepts it, and read a fresh machine's resolver as not in use — both measured on a lab machine (hq ADR 0100)

This commit is contained in:
2026-09-22 17:37:01 +02:00
parent 5e3dd3f59c
commit 3e0e6e6b7e
9 changed files with 699 additions and 17 deletions
+13 -2
View File
@@ -38,6 +38,17 @@ const (
Unsupported Kind = "unsupported"
)
// deletion is the arguments that delete a rule as `ufw show added` printed it. A route rule is
// deleted with `route delete …`: ufw refuses `delete route …` as invalid syntax. And ufw answers
// success when asked to delete a rule it does not hold, so every deletion is read back.
func deletion(rule string) []string {
w := words(rule)
if len(w) > 0 && w[0] == "route" {
return append([]string{"route", "delete"}, w[1:]...)
}
return append([]string{"delete"}, w...)
}
// MeshInterface is the private network's interface, the way an opening from the mesh is known.
// It must be the controller's overlay interface name.
const MeshInterface = "mesh0"
@@ -335,7 +346,7 @@ func Converge(ctx context.Context, run Runner, o *declaration.Opening) (string,
return "unchanged", nil
}
for _, rule := range stale {
if _, err := run(ctx, "ufw", append([]string{"delete"}, words(rule)...)...); err != nil {
if _, err := run(ctx, "ufw", deletion(rule)...); err != nil {
return "", fmt.Errorf("deleting the mesh's stale ufw rule %q: %w", rule, err)
}
}
@@ -381,7 +392,7 @@ func Remove(ctx context.Context, run Runner, id string) (int, error) {
if !markedFor(comment(rule), id) {
continue
}
if _, err := run(ctx, "ufw", append([]string{"delete"}, words(rule)...)...); err != nil {
if _, err := run(ctx, "ufw", deletion(rule)...); err != nil {
return removed, fmt.Errorf("deleting the mesh's ufw rule %q: %w", rule, err)
}
removed++