Skip to content

daemon: start a newly written fail2ban jail with a full reload - #288

Merged
ralyodio merged 1 commit into
masterfrom
fix/fail2ban-new-jail-reload
Oct 7, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/fail2ban-new-jail-reload

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #287, found while verifying it live on vienna (fail2ban backend). With /etc/fail2ban writable, the jail + filter files are created, then fail2ban-client reload threatcrush answers NOK: ('threatcrush',) because a new jail can't be reloaded by name, so the first ban still failed. Now: reload <jail>, falling back to a full reload (starts new jails, keeps existing bans). Confirmed on vienna by hand: after a full reload, threatcrush block lands in the jail and nft.

Tests: new fail2ban-new-jail.test.ts (fresh jail → full reload → banip; running jail → no reload). CLI suite 524/524, tsc clean.

🤖 Generated with Claude Code

`fail2ban-client reload threatcrush` only reloads a jail the server already
runs; for the jail threatcrushd has just written it answers NOK, so with the
EROFS fixed (#287) the first ban on a fail2ban box still failed. Fall back to
a plain `reload`, which starts new jails and keeps existing bans.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

18 finding(s)

HIGH/CRITICAL: 1 | MEDIUM: 9 | LOW: 8

Severity Rule Location
HIGH secret-aws-access-key prd/0003-detect-hardcoded-secrets-before-they-are-committed-or-served.md:126
MEDIUM sql-string-concatenation .github/workflows/migrate-dev2.yml:128
MEDIUM js-uninitialized-buffer apps/cli/src/core/log-tail.ts:58
MEDIUM js-open-redirect apps/web/src/app/auth/login/page.tsx:67
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:104
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:108
MEDIUM js-open-redirect apps/web/src/app/invite/[token]/invite-client.tsx:55
MEDIUM js-open-redirect apps/web/src/components/funding/FundingClient.tsx:97
MEDIUM js-unescaped-html-sink apps/web/src/components/GuideReader.tsx:265
MEDIUM js-uninitialized-buffer packages/scan/src/node-rules.ts:456
LOW secret-generic-credential apps/web/src/app/api/auth/refresh/route.ts:17
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:26
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:27
LOW secret-generic-credential PRD.md:269
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:121
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:122
LOW sh-remote-script-execution scripts/smoke-test.sh:72
LOW secret-aws-access-key scripts/smoke-test.sh:150

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 0929804 into master Oct 7, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant