Record the forward policies before disabling ufw, so a retried retirement restores them (hq ADR 0100)

This commit is contained in:
2026-09-22 18:33:09 +02:00
parent aef4993d10
commit 444ad8f3cf
5 changed files with 85 additions and 20 deletions
+7 -1
View File
@@ -30,6 +30,7 @@ func foundFirewall(ctx context.Context, d *declaration.Declaration, known *store
return "", err
}
rec.DisabledByMesh = false
rec.Forward = nil
log(" enabled ufw again: this node is adopted, and the firewall found on it is in force")
}
kind, name, err := firewall.Detect(ctx, run)
@@ -68,7 +69,12 @@ func retireFirewall(ctx context.Context, d *declaration.Declaration, origin stri
rec.DisabledByMesh {
return nil
}
if err := firewall.Disable(ctx, run); err != nil {
if rec.Forward == nil {
// Recorded before ufw is touched: disabling it opens the forward policy, and a retry
// must know what it was (novox/hq ADR 0100).
rec.Forward = firewall.ForwardPolicies(ctx, run)
}
if err := firewall.Disable(ctx, run, rec.Forward); err != nil {
return err
}
rec.DisabledByMesh = true