Retire the found firewall only once the mesh's own filter is loaded on the machine (hq ADR 0100)
This commit is contained in:
@@ -848,6 +848,30 @@ func Disable(ctx context.Context, run Runner, before map[string]string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// MeshTable is the derived filter's table, the thing that must be in force before the firewall
|
||||
// found on a machine is retired.
|
||||
const MeshTable = "inet mesh"
|
||||
|
||||
// MeshTableLoaded asks the machine whether the mesh's own filter is loaded. Read from the machine
|
||||
// rather than assumed from the declaration: a table declared and not loaded is exactly the case
|
||||
// where disabling the found firewall would leave the machine with nothing.
|
||||
func MeshTableLoaded(ctx context.Context, run Runner) (bool, error) {
|
||||
out, err := run(ctx, "nft", "list", "tables")
|
||||
if err != nil {
|
||||
if missing(err) {
|
||||
return false, nil
|
||||
}
|
||||
return false, fmt.Errorf("cannot read which tables this machine has loaded: %w", err)
|
||||
}
|
||||
for _, line := range strings.Split(out, "\n") {
|
||||
rest, ok := strings.CutPrefix(strings.TrimSpace(line), "table "+MeshTable)
|
||||
if ok && (rest == "" || strings.HasPrefix(rest, " ") || strings.HasPrefix(rest, "{")) {
|
||||
return true, nil
|
||||
}
|
||||
}
|
||||
return false, nil
|
||||
}
|
||||
|
||||
// ForwardPolicies reads each family's forward policy, by the tool that sets it. Read before ufw is
|
||||
// disabled and kept by the caller, so a retirement that fails half-way is retried with what the
|
||||
// machine had — not with what the half-done disable left.
|
||||
|
||||
Reference in New Issue
Block a user