Add no opening a found ufw rule already answers, since ufw takes rules differing only in comment for one, as captured on a lab machine (hq ADR 0103)

This commit is contained in:
2026-09-22 18:06:47 +02:00
parent da65f84c45
commit 52e139d96f
6 changed files with 433 additions and 28 deletions
+17
View File
@@ -287,3 +287,20 @@ func TestAFlipThatFailsKeepsTheGuardAndTheOpenings(t *testing.T) {
t.Error("the guard is still recorded after the completed flip")
}
}
func TestAnOpeningAFoundRuleAnswersIsReportedSatisfied(t *testing.T) {
// novox/hq ADR 0103: the mesh adds nothing beside a rule ufw would take for the same one.
dir := t.TempDir()
u := &ufwMachine{installed: true, active: true, rules: []string{"allow 22/tcp", "allow 5671/tcp"}}
report, _, err := applyWith(t, adopted(t, `{"taken":[]}`, busOpening+","+withConf(dir)), store.State{}, u.run)
if err != nil {
t.Fatal(err)
}
o := outcomeOf(report, "adoption.opening-tcp-5671-incoming")
if o.Action != "unchanged" || !strings.Contains(o.Detail, "satisfied by a rule found in ufw (allow 5671/tcp)") {
t.Errorf("the opening was not reported satisfied: %+v", o)
}
if len(u.rules) != 2 || u.index("ufw allow") >= 0 {
t.Errorf("a rule was added beside the found one: %v", u.rules)
}
}