From 5ef4699d05bc919255449a9af780f216a0589a72 Mon Sep 17 00:00:00 2001 From: Calvin Morrison Date: Wed, 19 Aug 2026 13:00:43 -0400 Subject: doc: 91 checks, and a wire Co-Authored-By: Claude Opus 5 --- fw/doc/todo.md | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) (limited to 'fw/doc/todo.md') diff --git a/fw/doc/todo.md b/fw/doc/todo.md index e83167d..fbb645a 100644 --- a/fw/doc/todo.md +++ b/fw/doc/todo.md @@ -5,8 +5,10 @@ says so; where it has not, it says what is actually true. An item never appears in both halves. `test/fwtest.rc` is a check for every bug that has shipped here, and -for the properties that must not quietly stop being true — 87 of them -now. Run it twice in a row after touching anything. +for the properties that must not quietly stop being true — 91 of them +now. Run it twice in a row after touching anything, and boot with +`run.sh -gw` or fourteen of them skip. `test/wire.md` is the part that +needs a second machine. ## Fixed, first round @@ -85,7 +87,11 @@ now. Run it twice in a row after touching anything. 10. **Promiscuous mode had no filter behind it.** The card must be promiscuous for multicast, but every neighbour's unicast was then judged, counted and flow-tracked as if it were ours. -11. **"A dead fw takes the network with it" was the requirement, not +11. **`/mnt/fw/ether0` was a name nothing made.** mntgen invents names + one level deep, so the mntgen over `/mnt` gives `/mnt/fw` and stops. + `fwstart` did it right by accident of being imperative; the service + file needed a second mntgen of its own, and now has one. +12. **"A dead fw takes the network with it" was the requirement, not the bug.** It had been item 1 since the beginning, on the grounds that a dead `fw` leaves the machine with no network. That is the only defensible thing for a firewall to do: the alternative is @@ -100,7 +106,7 @@ now. Run it twice in a row after touching anything. need the address it just lost, and `fw` clears the dead mount its own corpse left on the control mountpoint, which was refusing the restart by way of the check meant to protect the card. -12. **"fw daemonizes, so svc cannot supervise it" was wrong.** `svc` +13. **"fw daemonizes, so svc cannot supervise it" was wrong.** `svc` has had the detaching shape from the start: `ready=srv:` watches the `/srv` name, and for those services the process exiting "is normal and never causes a restart". Nothing needed a foreground -- cgit v1.2.3