Load the guard before removing the derived filter when a node returns to adopted, and defer the adoption's orphans only on the flip (hq ADR 0103)

This commit is contained in:
2026-09-22 18:30:13 +02:00
parent b531c47486
commit 491e04fb8f
2 changed files with 124 additions and 11 deletions
+66
View File
@@ -304,3 +304,69 @@ func TestAnOpeningAFoundRuleAnswersIsReportedSatisfied(t *testing.T) {
t.Errorf("a rule was added beside the found one: %v", u.rules)
}
}
// Defends novox/hq ADR 0103: returned to adopted, the guard is up before the derived filter's
// orphans go, and stays up if removing them fails.
func TestReturningToAdoptedLoadsTheGuardBeforeRemovingTheFilter(t *testing.T) {
dir := t.TempDir()
guard := filepath.Join(dir, "guard.nft")
guardFile := `{"id":"adoption.guard","type":"file","path":"` + guard + `","content":"table inet mesh_guard {}\n"}`
for _, stopFails := range []bool{false, true} {
_ = os.Remove(guard)
guardUpAtStop := false
run := func(_ context.Context, name string, args ...string) (string, error) {
if name != "systemctl" {
return "", &exec.Error{Name: name, Err: exec.ErrNotFound}
}
switch args[0] {
case "show":
return "LoadState=loaded\nActiveState=active\nType=oneshot\nRemainAfterExit=yes\n", nil
case "stop":
_, err := os.Stat(guard)
guardUpAtStop = err == nil
if stopFails {
return "", errors.New("the filter would not stop")
}
}
return "", nil
}
converged := store.State{Resources: []store.Applied{
{ID: "nftables.load", Type: "service", Target: "mesh-filter.service", Origin: store.OriginDeclared}}}
_, state, err := applyWith(t, adopted(t, `{"taken":[]}`, withConf(dir)+","+guardFile), converged, run)
if !guardUpAtStop {
t.Errorf("stop fails %v: the derived filter was stopped before the guard was written", stopFails)
}
if stopFails {
if err == nil {
t.Error("a failed removal was not reported")
}
if _, statErr := os.Stat(guard); statErr != nil {
t.Error("the guard is not up after the filter's removal failed")
}
if _, ok := state.Find("adoption.guard"); !ok {
t.Error("the guard applied before the failure was not recorded")
}
} else if err != nil {
t.Fatal(err)
}
}
}
func TestAStaleOpeningOnAnAdoptedNodeIsRemovedAsAnyOrphan(t *testing.T) {
// Only the flip defers the adoption's own orphans; an adopted node drops a stale opening at
// once, before what replaces it is applied.
dir := t.TempDir()
u := &ufwMachine{installed: true, active: true, rules: []string{"allow 22/tcp"}}
_, state, err := applyWith(t, adopted(t, `{"taken":[]}`, busOpening+","+withConf(dir)), store.State{}, u.run)
if err != nil {
t.Fatal(err)
}
u.asked = nil
other := `{"id":"adoption.opening-tcp-5000-incoming","type":"opening","port":5000,"protocol":"tcp","from":"everywhere","path":"incoming"}`
if _, _, err = applyWith(t, adopted(t, `{"taken":[]}`, other+","+withConf(dir)), state, u.run); err != nil {
t.Fatal(err)
}
if del, add := u.index("ufw delete"), u.index("ufw allow"); del < 0 || add < 0 || del > add {
t.Errorf("the stale opening was not removed before the new one was added: %v", u.asked)
}
}