Retire the found firewall only once the mesh's own filter is loaded on the machine (hq ADR 0100)

This commit is contained in:
2026-09-22 19:54:43 +02:00
parent 5f126021b7
commit 9839006d48
3 changed files with 70 additions and 2 deletions
+13
View File
@@ -69,6 +69,19 @@ func retireFirewall(ctx context.Context, d *declaration.Declaration, origin stri
rec.DisabledByMesh {
return nil
}
// **Nothing is retired until what replaces it is in force** (novox/hq ADR 0100). The flip
// loads the mesh's derived filter in ufw's place; disabling ufw before that table is actually
// loaded — a filter module not assigned, or a unit that did not load — leaves the machine with
// no filter at all.
loaded, err := firewall.MeshTableLoaded(ctx, run)
if err != nil {
return err
}
if !loaded {
return fmt.Errorf("this node is converged and the mesh's own filter (table %s) is not loaded on "+
"this machine, so ufw was left in force: retiring it would leave the machine filtering "+
"nothing. Assign a filter module to this node, or return it to adopted", firewall.MeshTable)
}
if rec.Forward == nil {
// Recorded before ufw is touched: disabling it opens the forward policy, and a retry
// must know what it was (novox/hq ADR 0100).