Record the forward policies before disabling ufw, so a retried retirement restores them (hq ADR 0100)
This commit is contained in:
@@ -30,6 +30,7 @@ func foundFirewall(ctx context.Context, d *declaration.Declaration, known *store
|
||||
return "", err
|
||||
}
|
||||
rec.DisabledByMesh = false
|
||||
rec.Forward = nil
|
||||
log(" enabled ufw again: this node is adopted, and the firewall found on it is in force")
|
||||
}
|
||||
kind, name, err := firewall.Detect(ctx, run)
|
||||
@@ -68,7 +69,12 @@ func retireFirewall(ctx context.Context, d *declaration.Declaration, origin stri
|
||||
rec.DisabledByMesh {
|
||||
return nil
|
||||
}
|
||||
if err := firewall.Disable(ctx, run); err != nil {
|
||||
if rec.Forward == nil {
|
||||
// Recorded before ufw is touched: disabling it opens the forward policy, and a retry
|
||||
// must know what it was (novox/hq ADR 0100).
|
||||
rec.Forward = firewall.ForwardPolicies(ctx, run)
|
||||
}
|
||||
if err := firewall.Disable(ctx, run, rec.Forward); err != nil {
|
||||
return err
|
||||
}
|
||||
rec.DisabledByMesh = true
|
||||
|
||||
Reference in New Issue
Block a user