Retire the found firewall only once the mesh's own filter is loaded on the machine (hq ADR 0100)

This commit is contained in:
2026-09-22 19:54:43 +02:00
parent 5f126021b7
commit 9839006d48
3 changed files with 70 additions and 2 deletions
+24
View File
@@ -848,6 +848,30 @@ func Disable(ctx context.Context, run Runner, before map[string]string) error {
return nil
}
// MeshTable is the derived filter's table, the thing that must be in force before the firewall
// found on a machine is retired.
const MeshTable = "inet mesh"
// MeshTableLoaded asks the machine whether the mesh's own filter is loaded. Read from the machine
// rather than assumed from the declaration: a table declared and not loaded is exactly the case
// where disabling the found firewall would leave the machine with nothing.
func MeshTableLoaded(ctx context.Context, run Runner) (bool, error) {
out, err := run(ctx, "nft", "list", "tables")
if err != nil {
if missing(err) {
return false, nil
}
return false, fmt.Errorf("cannot read which tables this machine has loaded: %w", err)
}
for _, line := range strings.Split(out, "\n") {
rest, ok := strings.CutPrefix(strings.TrimSpace(line), "table "+MeshTable)
if ok && (rest == "" || strings.HasPrefix(rest, " ") || strings.HasPrefix(rest, "{")) {
return true, nil
}
}
return false, nil
}
// ForwardPolicies reads each family's forward policy, by the tool that sets it. Read before ufw is
// disabled and kept by the caller, so a retirement that fails half-way is retried with what the
// machine had — not with what the half-done disable left.