diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index 6854092..13538cb 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -1195,12 +1195,15 @@ test("the hub can be filtered without severing the mesh", { // The failure this guards against is not subtle and is very hard to recover from: a rule set // that closes the hub's own port takes the private network down, and the mesh's way of fixing // anything is to send a declaration over it. - const rules = "/etc/mesh/hub-filter.nft"; + // Its own directory. Another module on this machine already declares /etc/mesh, and the mesh + // refuses two modules declaring one path rather than letting the second quietly win — which it + // did here, correctly, the first time this ran. + const rules = "/etc/mesh-hub/filter.nft"; await must("anchor", `printf %s '{"module":"hubfilter","version":"1",` + `"capabilities":["firewall"],` + `"filtering":{"into":"${rules}"},` + `"resources":[{"id":"nftables","type":"package","package":"nftables"},` + - `{"id":"dir","type":"directory","path":"/etc/mesh","mode":"0755"},` + + `{"id":"dir","type":"directory","path":"/etc/mesh-hub","mode":"0755"},` + `{"id":"unit","type":"file","path":"/etc/systemd/system/hub-filter.service",` + `"mode":"0644","content":"[Unit]\\nDescription=What the mesh computed for the hub\\n` + `[Service]\\nType=oneshot\\nRemainAfterExit=yes\\n` + @@ -1218,7 +1221,9 @@ test("the hub can be filtered without severing the mesh", { const written = await must("anchor", `cat ${rules}`); assert.match(written, /udp dport 51820 accept/, `the hub's rule set closes the private network it is the way onto:\n${written}`); - assert.match(written, /# networking/, + // The module that provides the private network, not the requirement it answers: `networking` + // is the domain a module offers, and what caused a rule is the module itself. + assert.match(written, /# mesh-wireguard — the private network/, `the rule does not name what caused it:\n${written}`); // Loaded, and the mesh still works: a declaration reaches the other machine, which it cannot if