Files
fips/packaging/debian
Johnathan Corgan f4b2632646 Reapply the firewall ruleset in place when the package is upgraded
On upgrade the package reloaded nothing: fips-firewall.service kept the ruleset
loaded at boot, so a changed /etc/fips/fips.nft did not take effect until the
next reboot or a manual restart, and a restart runs ExecStop, which deletes the
fips table and leaves the mesh interface unfiltered until ExecStart loads it
again.

fips-firewall.service, in both the Debian and the plain systemd unit, gains an
ExecReload that runs the same nft -f. The file adds and then flushes the table
before defining it, so one run replaces the ruleset in a single transaction.
postinst now runs try-reload-or-restart on the unit before it starts the
daemon. That acts only when the unit is already active, so it never turns the
firewall on for a host that has not opted in, and a reload that fails leaves the
previous ruleset in place, so it is reported and the upgrade goes on.

The upgrade scenario gains a host with the firewall enabled. Its newer package
carries a ruleset with an extra named counter; after the upgrade the counter
must be loaded, and an nft monitor running across the upgrade, proven to be
recording first, must show no deletion of the fips table. The host that never
opted in must still have the firewall inactive, disabled and its table absent.
2026-09-19 02:52:06 +00:00
..