Add no opening a found ufw rule already answers, since ufw takes rules differing only in comment for one, as captured on a lab machine (hq ADR 0103)

This commit is contained in:
2026-09-22 18:06:47 +02:00
parent da65f84c45
commit 52e139d96f
6 changed files with 433 additions and 28 deletions
+8 -2
View File
@@ -85,12 +85,18 @@ func applyOpening(ctx context.Context, o *declaration.Opening, run Runner, kind
out.Detail = "no firewall found; nothing filters this port"
return out, nil
case firewall.UFW:
action, err := firewall.Converge(ctx, run, o)
done, err := firewall.Converge(ctx, run, o)
if err != nil {
return out, err
}
out.Action = action
out.Action = done.Action
out.Detail = "through ufw, marked " + firewall.Mark(o)
if done.SatisfiedBy != "" {
// ufw would take a rule differing only in its comment for the same one, so the
// mesh's is not added beside it (novox/hq ADR 0103).
out.Detail = "satisfied by a rule found in ufw (" + done.SatisfiedBy +
"); the mesh added nothing and will remove nothing"
}
return out, nil
}
return out, fmt.Errorf("no firewall is known for this node, so %s cannot be opened", o.Target())