Add mtime TOCTOU check and wildcard flag to ConfigReloadHandle (ADR-029/030)
Extract shared read_and_validate_config() with before/after mtime check to detect mid-write config file changes. Add ReloadError enum with FileChangedDuringRead variant. Return HTTP 409 Conflict on mtime change from admin reload endpoint. Store cli_allow_wildcard_bind in ConfigReloadHandle and use it in reload() validation instead of hardcoded false. Update all ConfigReloadHandle::new() call sites.
This commit is contained in:
1 parent
3ea3f56de7
commit
c6dda716f4
7 files changed
+335
-41
No files matched your search
@@ -865,6 +865,7 @@ async fn test_sighup_config_reload_valid_config() {
|
||||
let reload_handle = Arc::new(reverse_proxy::config::ConfigReloadHandle::new(
|
||||
config_arc.clone(),
|
||||
static_config,
|
||||
false,
|
||||
));
|
||||
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
@@ -892,8 +893,8 @@ https_port = 443
|
||||
mode = "acme"
|
||||
acme_domains = ["test.local"]
|
||||
acme_cache_dir = "/tmp/acme-cache"
|
||||
acme_contact = "mailto:admin@test.local"
|
||||
acme_directory = "staging"
|
||||
acme_contact = "mailto:admin@test.local"
|
||||
|
||||
[[listeners.sites]]
|
||||
host = "test.local"
|
||||
@@ -921,6 +922,7 @@ async fn test_sighup_config_reload_invalid_config_keeps_old() {
|
||||
let reload_handle = Arc::new(reverse_proxy::config::ConfigReloadHandle::new(
|
||||
config_arc.clone(),
|
||||
static_config,
|
||||
false,
|
||||
));
|
||||
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
|
||||
Reference in new issue
Block a user