Add no opening a found ufw rule already answers, since ufw takes rules differing only in comment for one, as captured on a lab machine (hq ADR 0103)
This commit is contained in:
@@ -85,12 +85,18 @@ func applyOpening(ctx context.Context, o *declaration.Opening, run Runner, kind
|
||||
out.Detail = "no firewall found; nothing filters this port"
|
||||
return out, nil
|
||||
case firewall.UFW:
|
||||
action, err := firewall.Converge(ctx, run, o)
|
||||
done, err := firewall.Converge(ctx, run, o)
|
||||
if err != nil {
|
||||
return out, err
|
||||
}
|
||||
out.Action = action
|
||||
out.Action = done.Action
|
||||
out.Detail = "through ufw, marked " + firewall.Mark(o)
|
||||
if done.SatisfiedBy != "" {
|
||||
// ufw would take a rule differing only in its comment for the same one, so the
|
||||
// mesh's is not added beside it (novox/hq ADR 0103).
|
||||
out.Detail = "satisfied by a rule found in ufw (" + done.SatisfiedBy +
|
||||
"); the mesh added nothing and will remove nothing"
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
return out, fmt.Errorf("no firewall is known for this node, so %s cannot be opened", o.Target())
|
||||
|
||||
@@ -287,3 +287,20 @@ func TestAFlipThatFailsKeepsTheGuardAndTheOpenings(t *testing.T) {
|
||||
t.Error("the guard is still recorded after the completed flip")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnOpeningAFoundRuleAnswersIsReportedSatisfied(t *testing.T) {
|
||||
// novox/hq ADR 0103: the mesh adds nothing beside a rule ufw would take for the same one.
|
||||
dir := t.TempDir()
|
||||
u := &ufwMachine{installed: true, active: true, rules: []string{"allow 22/tcp", "allow 5671/tcp"}}
|
||||
report, _, err := applyWith(t, adopted(t, `{"taken":[]}`, busOpening+","+withConf(dir)), store.State{}, u.run)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
o := outcomeOf(report, "adoption.opening-tcp-5671-incoming")
|
||||
if o.Action != "unchanged" || !strings.Contains(o.Detail, "satisfied by a rule found in ufw (allow 5671/tcp)") {
|
||||
t.Errorf("the opening was not reported satisfied: %+v", o)
|
||||
}
|
||||
if len(u.rules) != 2 || u.index("ufw allow") >= 0 {
|
||||
t.Errorf("a rule was added beside the found one: %v", u.rules)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user