swarm-bao: don't let the viewer restart enqueue fail the granter
ExecStartPost (not postStart, which can't take a prefix) with a leading -: a failed enqueue -- an already-running viewer unit, or systemctl itself failing -- must not mark the granter failed or trigger its own Restart=on-failure.
This commit is contained in:
parent
22c96282b9
commit
8fb7751da9
2 changed files with 22 additions and 13 deletions
|
|
@ -1492,14 +1492,18 @@ let
|
|||
# success restarts that unit: a restart since the unit is
|
||||
# `RemainAfterExit`, `--no-block` since it is ordered after the granter.
|
||||
# The ordering is one-way, so the viewer's retries never reach back.
|
||||
name = "a successful granter step restarts the viewer unit without blocking";
|
||||
# `ExecStartPost` directly, not `postStart` (which can't carry a
|
||||
# leading `-`), and the `-` is load-bearing: a failed enqueue must not
|
||||
# mark the granter itself failed.
|
||||
name = "a successful granter step restarts the viewer unit without blocking, and the enqueue can't fail the granter";
|
||||
ok =
|
||||
let
|
||||
s = baoGrantHere.systemd.services;
|
||||
g = s.swarm-bao-granter-role;
|
||||
v = s.swarm-bao-operator-viewer-policy;
|
||||
in
|
||||
lib.hasInfix "systemctl restart --no-block swarm-bao-operator-viewer-policy.service" g.postStart
|
||||
lib.hasPrefix "-" g.serviceConfig.ExecStartPost
|
||||
&& lib.hasInfix "systemctl restart --no-block swarm-bao-operator-viewer-policy.service" g.serviceConfig.ExecStartPost
|
||||
&& lib.elem "swarm-bao-granter-role.service" v.after
|
||||
&& !(lib.elem "swarm-bao-operator-viewer-policy.service" g.after)
|
||||
&& !(v ? postStart && lib.hasInfix "swarm-bao-granter-role" v.postStart);
|
||||
|
|
|
|||
Loading…
Reference in a new issue