Retire the found firewall only on a converged declaration from the mesh, never on a carried apply (hq ADR 0100)

This commit is contained in:
2026-09-22 18:01:49 +02:00
parent c989b57439
commit 9033e3da98
3 changed files with 30 additions and 4 deletions
+22
View File
@@ -202,3 +202,25 @@ func TestAnOpeningOnAConvergedNodeIsRefused(t *testing.T) {
t.Error("an opening was accepted on a node the declaration does not say is adopted")
}
}
func TestACarriedApplyOnAnAdoptedNodeLeavesItsFirewallInForce(t *testing.T) {
// The bundle, re-applied by the installer or the one-shot CLI, never says a node is adopted.
// That is not the controller converging it, so ufw must stay enabled (novox/hq ADR 0100).
dir := t.TempDir()
u := &ufwMachine{installed: true, active: true, rules: []string{"allow 22/tcp"}}
_, state, err := applyWith(t, adopted(t, `{"taken":[]}`, busOpening+","+withConf(dir)), store.State{}, u.run)
if err != nil {
t.Fatal(err)
}
u.asked = nil
carried := parse(t, `{"declaration":1,"resources":[`+withConf(filepath.Join(dir, "bundle"))+`]}`)
_, state, err = ApplyKeeping(context.Background(), archHost(t), carried, state, store.OriginCarried,
u.run, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
if !u.active || state.Firewall.DisabledByMesh || u.index("ufw disable") >= 0 {
t.Fatalf("a carried apply retired the found firewall: active %v, record %+v, asked %v",
u.active, state.Firewall, u.asked)
}
}