The mesh's own ban chain is a ban wherever it hangs; the front end's record is cited as 0180 (hq ADR 0186)
The legacy reader required every path into a chain of refusals to come from a built-in whose policy accepts. The home server's ban chain hangs off the container runtime's user chain, whose forward policy the runtime set to DROP, so the machine reported the mesh's own intrusion prevention as a rule set the mesh did not write. A chain is a ban when every refusal names its sources and the chain accepts nothing — the rule the nftables side already used. A chain that accepts anything is still not a ban. Fixture captured from the machine. The citations for the uninstalled front end move to ADR 0180, which another session's renumber had left pointing at an unrelated record.
This commit is contained in:
@@ -1443,7 +1443,7 @@ func applyPackage(ctx context.Context, sys system.System, r *declaration.Package
|
||||
return out, err
|
||||
}
|
||||
if r.Absent {
|
||||
// Declared absent (novox/hq ADR 0175): removed when it is here, left alone when it is not.
|
||||
// Declared absent (novox/hq ADR 0180): removed when it is here, left alone when it is not.
|
||||
if !installed {
|
||||
out.Action = "unchanged"
|
||||
out.Detail = "not installed, as declared"
|
||||
|
||||
@@ -174,7 +174,7 @@ func TestACapabilityReachesTheRuntimeAndTheSpec(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// A package may be declared absent (novox/hq ADR 0175): removed when it is installed, read back,
|
||||
// A package may be declared absent (novox/hq ADR 0180): removed when it is installed, read back,
|
||||
// left alone when it is not.
|
||||
func TestAPackageDeclaredAbsentIsRemovedWhenPresentAndLeftWhenNot(t *testing.T) {
|
||||
installed := true
|
||||
|
||||
@@ -77,7 +77,7 @@ func retireFirewall(ctx context.Context, d *declaration.Declaration, origin stri
|
||||
return "", nil
|
||||
}
|
||||
if !firewall.Installed(ctx, run) {
|
||||
// Uninstalled (novox/hq ADR 0175): retired for good, by the module that replaced it. Said
|
||||
// Uninstalled (novox/hq ADR 0180): retired for good, by the module that replaced it. Said
|
||||
// once, and nothing is asked of a command that is not there.
|
||||
if rec.RetiredBy != firewall.RetiredRemoved {
|
||||
rec.RetiredBy = firewall.RetiredRemoved
|
||||
|
||||
@@ -525,7 +525,7 @@ func TestUfwIsNotRetiredUntilTheMeshsOwnFilterIsLoaded(t *testing.T) {
|
||||
}
|
||||
|
||||
// A front end that is no longer installed is recorded as removed, said once, and asked nothing of
|
||||
// (novox/hq ADR 0175).
|
||||
// (novox/hq ADR 0180).
|
||||
func TestAnUninstalledFrontEndIsRetiredForGood(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
u := &ufwMachine{installed: false, ruleset: "table inet mesh\n"}
|
||||
|
||||
@@ -2,6 +2,7 @@ package apply
|
||||
|
||||
import (
|
||||
"context"
|
||||
"os"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
@@ -89,3 +90,11 @@ func TestAServiceAskedToStopIsNotWaitedOn(t *testing.T) {
|
||||
t.Fatalf("stopping a service was reported as a failure: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// The settle between a unit's two read-backs is a real pause on a machine and nothing in a test:
|
||||
// no test here drives a service manager that takes time, so paying it would only slow the suite
|
||||
// (novox/hq ADR 0184).
|
||||
func TestMain(m *testing.M) {
|
||||
serviceSettle = 0
|
||||
os.Exit(m.Run())
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user