Record the forward policies before disabling ufw, so a retried retirement restores them (hq ADR 0100)

This commit is contained in:
2026-09-22 18:33:09 +02:00
parent aef4993d10
commit 444ad8f3cf
5 changed files with 85 additions and 20 deletions
+3 -3
View File
@@ -356,7 +356,7 @@ func TestRemovingAnOpeningRemovesOnlyWhatWasMarkedForIt(t *testing.T) {
func TestEnableAndDisableReadBack(t *testing.T) {
f := &fakeUFW{installed: true, active: true}
if err := Disable(context.Background(), f.run); err != nil || f.active {
if err := Disable(context.Background(), f.run, nil); err != nil || f.active {
t.Fatalf("disable: %v", err)
}
if err := Enable(context.Background(), f.run); err != nil || !f.active {
@@ -493,7 +493,7 @@ func TestRetiringUfwKeepsTheMachineFromRoutingForOthers(t *testing.T) {
t.Fatal("the captures no longer show ufw disable opening the forward policy")
}
f := &fakeUFW{installed: true, active: true, iptablesActive: string(before), iptablesInactive: string(after)}
if err := Disable(context.Background(), f.run); err != nil {
if err := Disable(context.Background(), f.run, ForwardPolicies(context.Background(), f.run)); err != nil {
t.Fatal(err)
}
if f.active {
@@ -511,7 +511,7 @@ func TestRetiringUfwKeepsTheMachineFromRoutingForOthers(t *testing.T) {
func TestRetiringUfwOnAMachineWithoutIptablesStillRetiresIt(t *testing.T) {
f := &fakeUFW{installed: true, active: true}
if err := Disable(context.Background(), f.run); err != nil || f.active {
if err := Disable(context.Background(), f.run, nil); err != nil || f.active {
t.Fatalf("disable: %v, active %v", err, f.active)
}
}