summaryrefslogtreecommitdiff
path: root/fw/doc
diff options
context:
space:
mode:
Diffstat (limited to 'fw/doc')
-rw-r--r--fw/doc/design.md9
-rw-r--r--fw/doc/todo.md29
2 files changed, 28 insertions, 10 deletions
diff --git a/fw/doc/design.md b/fw/doc/design.md
index c14787c..1060ba6 100644
--- a/fw/doc/design.md
+++ b/fw/doc/design.md
@@ -143,6 +143,15 @@ forbid are dropped. pf and iptables leave them running until they time
out; that is a wart everyone has to learn, and "I blocked it, why is the
transfer still going" is the wrong thing to discover at 3am.
+**A file server, so it detaches.** `fw` posts to `/srv`, forks the
+server and lets the process you started exit — what 42 of the 47 file
+servers in `/sys/src/cmd` do, and the five that do not are stdio
+servers speaking 9P on their own standard input, which is a different
+thing altogether. So a supervisor watches the `/srv` name and not the
+pid, which `svc` already provides for. The name is only worth watching
+if it is honest, which is why anything that stops one part of `fw` now
+stops all of it.
+
**Per-rule logging to `/sys/log/fw`.** Global logging either floods a
disk or tells you nothing. `syslog(2)` does not create its file, so `fw`
says so at startup rather than dropping the lines silently.
diff --git a/fw/doc/todo.md b/fw/doc/todo.md
index de5eb8e..d101989 100644
--- a/fw/doc/todo.md
+++ b/fw/doc/todo.md
@@ -4,7 +4,7 @@ Most of this came from code review. Where a finding has been fixed it
says so; where it has not, it says what is actually true. An item never
appears in both halves.
-`test/fwtest.rc` is a check for every bug that has shipped here — 72 of
+`test/fwtest.rc` is a check for every bug that has shipped here — 77 of
them now. Run it twice in a row after touching anything.
## Fixed, first round
@@ -84,6 +84,16 @@ them now. Run it twice in a row after touching anything.
10. **Promiscuous mode had no filter behind it.** The card must be
promiscuous for multicast, but every neighbour's unicast was then
judged, counted and flow-tracked as if it were ours.
+11. **"fw daemonizes, so svc cannot supervise it" was wrong.** `svc`
+ has had the detaching shape from the start: `ready=srv:` watches
+ the `/srv` name, and for those services the process exiting "is
+ normal and never causes a restart". Nothing needed a foreground
+ mode. What was true underneath it: the control filesystem going
+ away ended the server proc and left the relays filtering, so the
+ `/srv` name could be gone while the firewall was still running.
+ Now any part stopping stops all of them, which is what makes the
+ name worth watching. `fwstart` is still the wrong shape; a service
+ file per card is in `lib/svc`.
## Still open
@@ -98,19 +108,18 @@ card is the address that just vanished.
The cleanup that claimed to handle this was dead code and is gone. The
answer is not more note handling — it has to be something that outlives
`fw`, which means the supervisor, with the address stored where `fw`
-does not own it. This also blocks `svc` supervision.
+does not own it.
-### 2. fw daemonizes, so svc cannot supervise it
+This is what makes `restart=always` a half-measure rather than an
+answer: `svc` will start `fw` again, and the new one has no address to
+read off a card that no longer has one. It needs `-a`, or the card
+configured again first. Supervision works; recovery does not.
-Needs a foreground mode; `ready=srv:name` fits, since `-s` already
-posts to `/srv`. `fwstart` is the wrong shape and should probably go —
-one service per card is the right one.
-
-### 3. One card per fw, and rules cannot name a card
+### 2. One card per fw, and rules cannot name a card
Wants repeatable `-e` and an `ifc=` attribute, together.
-### 4. Tflush is not implemented
+### 3. Tflush is not implemented
A request `fw` is blocked on cannot be abandoned. Only affects
namespace mode, where waiting for an inbound connection is the one
@@ -118,7 +127,7 @@ operation that blocks indefinitely. ~80 lines, with a race that cannot
be fully closed: between the syscall returning and the handler clearing
its entry, a note may land on a worker that has moved on.
-### 5. Positional `delete n` renumbers
+### 4. Positional `delete n` renumbers
Inherent to positional deletion; iptables has it too. Said out loud
here rather than fixed.