status: cancel-all reverts pending changes to last applied config
- lib.common.revert_to_applied(): restore a config file from its
_last_applied_config snapshot (stamped hash); no baseline -> skip with
reason, file untouched
- firewall config_apply now stamps the applied baseline like the other
subsystems; GET /firewall/config and the state collector strip the
internal _last_applied_* keys
- POST /status/cancel-all + /api/status/cancel-all: revert pending
subsystems, {cancelled, skipped, errors}, partial-failure safe
- dashboard: "Cancel All Changes" button with confirm modal
(CancelConfirm, reuses the pending-changes modal rows); the pending
changes card is hidden entirely when nothing is pending
- tests: revert_to_applied, status_cancel_all, firewall stamping/meta
stripping, /api/status/cancel-all route, node tests for CancelConfirm;
firewall _config_apply tests no longer write the real repo config
- docs: api.md, state-model.md, config.md, hoover.md
This commit is contained in:
@@ -34,7 +34,7 @@ from daemon.iface import (
|
||||
POST_FIREWALL_ZONES_SERVICES,
|
||||
)
|
||||
from daemon.server import ConflictError, NotFoundError, refresh_state, registry
|
||||
from lib.common import load_json, run, save_json
|
||||
from lib.common import load_json, run, save_json, stamp_applied, strip_apply_meta
|
||||
from lib.firewall import (
|
||||
_normalize_target,
|
||||
_parse_active_zones,
|
||||
@@ -391,6 +391,11 @@ def _config_apply(force: bool = False) -> dict[str, Any]:
|
||||
"timestamp": "",
|
||||
}
|
||||
backup_path = _save_backup(full_state)
|
||||
# Record the applied config snapshot + hash so pending-changes detection
|
||||
# and cancel/revert work like the hash-based subsystems.
|
||||
applied_cfg = _get_config()
|
||||
stamp_applied(applied_cfg)
|
||||
_save_config(applied_cfg)
|
||||
logger.info("Firewall config applied to %d zones", len(applied))
|
||||
return {
|
||||
"applied_zones": applied,
|
||||
@@ -506,9 +511,9 @@ def get_config(_request: Any, _body: Any) -> dict[str, Any]:
|
||||
_body: The request body (unused).
|
||||
|
||||
Returns:
|
||||
Full firewall config dict.
|
||||
Full firewall config dict (apply bookkeeping keys stripped).
|
||||
"""
|
||||
return _get_config()
|
||||
return strip_apply_meta(_get_config())
|
||||
|
||||
|
||||
@registry.register(POST_FIREWALL_CONFIG)
|
||||
|
||||
@@ -1,21 +1,33 @@
|
||||
"""Aggregate status handler.
|
||||
|
||||
Exposes pending changes across all subsystems and a single apply-all
|
||||
endpoint that invokes each subsystem's apply in the correct order.
|
||||
Exposes pending changes across all subsystems, a single apply-all
|
||||
endpoint that invokes each subsystem's apply in the correct order, and a
|
||||
cancel-all endpoint that reverts pending edits to the last applied config.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import logging
|
||||
from pathlib import Path
|
||||
from typing import Any
|
||||
|
||||
from daemon.handlers import dnsmasq as _dnsmasq_h
|
||||
from daemon.handlers import firewall as _firewall_h
|
||||
from daemon.handlers import nginx as _nginx_h
|
||||
from daemon.handlers.dnsmasq import apply_config as dnsmasq_apply_config
|
||||
from daemon.handlers.firewall import config_apply as firewall_config_apply
|
||||
from daemon.handlers.network import apply_all as network_apply_all
|
||||
from daemon.handlers.nginx import apply as nginx_apply
|
||||
from daemon.handlers.wireguard import apply as wireguard_apply
|
||||
from daemon.iface import GET_STATUS_PENDING, POST_STATUS_APPLY_ALL
|
||||
from daemon.iface import (
|
||||
GET_STATUS_PENDING,
|
||||
POST_STATUS_APPLY_ALL,
|
||||
POST_STATUS_CANCEL_ALL,
|
||||
)
|
||||
from daemon.server import refresh_state, registry
|
||||
from lib import network as _net
|
||||
from lib import wireguard as _wg
|
||||
from lib.common import revert_to_applied
|
||||
from lib.firewall import fw_change_summary
|
||||
from lib.state import state as state_store
|
||||
|
||||
@@ -36,6 +48,15 @@ SYS_APPLY = {
|
||||
"dnsmasq": dnsmasq_apply_config,
|
||||
"nginx": nginx_apply,
|
||||
}
|
||||
# (module, attribute) pairs for each subsystem's on-disk config path.
|
||||
# Resolved at call time so tests can monkeypatch the module constants.
|
||||
SYS_CONFIG_PATHS: dict[str, tuple[Any, str]] = {
|
||||
"firewall": (_firewall_h, "CONFIG_FILE"),
|
||||
"dnsmasq": (_dnsmasq_h, "CONFIG_PATH"),
|
||||
"nginx": (_nginx_h, "CONFIG_FILE"),
|
||||
"wireguard": (_wg, "CONFIG_PATH"),
|
||||
"networkd": (_net, "CONFIG_FILE"),
|
||||
}
|
||||
|
||||
|
||||
@registry.register(GET_STATUS_PENDING)
|
||||
@@ -126,6 +147,65 @@ def status_apply_all(_request: Any, _body: Any) -> dict[str, Any]:
|
||||
return {"applied": applied, "errors": errors}
|
||||
|
||||
|
||||
def _config_path(name: str) -> Path:
|
||||
"""Return the on-disk config path for subsystem *name*.
|
||||
|
||||
Resolved via the owning module at call time so tests can monkeypatch
|
||||
the module constants (e.g. ``lib.wireguard.CONFIG_PATH``).
|
||||
"""
|
||||
module, attr = SYS_CONFIG_PATHS[name]
|
||||
return getattr(module, attr)
|
||||
|
||||
|
||||
@registry.register(POST_STATUS_CANCEL_ALL)
|
||||
def status_cancel_all(_request: Any, _body: Any) -> dict[str, Any]:
|
||||
"""Revert pending changes for all subsystems to the last applied config.
|
||||
|
||||
Restores each pending subsystem's config file from its recorded
|
||||
``_last_applied_config`` snapshot, discarding unapplied edits.
|
||||
Subsystems without a recorded baseline (never applied) are skipped
|
||||
with a reason instead of being reset. No live-system commands run —
|
||||
cancel only touches the declarative config files.
|
||||
|
||||
Returns:
|
||||
Dict with ``cancelled`` (list of reverted subsystems),
|
||||
``skipped`` (label -> reason), and ``errors`` (label -> message).
|
||||
"""
|
||||
pending_data = status_pending(None, None)
|
||||
fw_pending = pending_data["firewall"]["needs_apply"]
|
||||
hash_pending = {
|
||||
"dnsmasq": pending_data["dnsmasq"]["pending_changes"],
|
||||
"nginx": pending_data["nginx"]["pending_changes"],
|
||||
"wireguard": pending_data["wireguard"]["pending_changes"],
|
||||
"networkd": pending_data["networkd"]["pending_changes"],
|
||||
}
|
||||
|
||||
cancelled: list[str] = []
|
||||
skipped: dict[str, str] = {}
|
||||
errors: dict[str, str] = {}
|
||||
|
||||
for name in SYS_ORDER:
|
||||
pending = fw_pending if name == "firewall" else hash_pending.get(name, False)
|
||||
if not pending:
|
||||
continue
|
||||
label = SYS_LABELS.get(name, name)
|
||||
try:
|
||||
ok, reason = revert_to_applied(_config_path(name))
|
||||
if ok:
|
||||
cancelled.append(name)
|
||||
logger.info("Cancelled pending changes for %s", name)
|
||||
else:
|
||||
skipped[label] = reason
|
||||
logger.warning("Cancel-all skipped %s: %s", label, reason)
|
||||
except Exception as exc:
|
||||
errors[label] = str(exc)
|
||||
logger.error("Cancel-all failed for %s: %s", name, exc)
|
||||
|
||||
if cancelled:
|
||||
refresh_state(SYS_ORDER)
|
||||
return {"cancelled": cancelled, "skipped": skipped, "errors": errors}
|
||||
|
||||
|
||||
def _hash_subsystem(name: str, state: dict[str, Any] | None) -> dict[str, Any]:
|
||||
"""Build pending result for a hash-based subsystem."""
|
||||
if state is None:
|
||||
|
||||
Reference in New Issue
Block a user