[PR #6526] [management] When collecting group and peer IDs from policies, do so directionally #28378

Open
opened 2026-08-05 08:06:15 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6526
Author: @dmitri-netbird
Created: 6/23/2026
Status: 🔄 Open

Base: mainHead: dmitri-filter-policies-by-direction


📝 Commits (7)

  • 7873f33 when collecting group and peer IDs from policies, do so directionally
  • 4c4434a fixed a few tests
  • 33954ea fixing tests + adding tests
  • 9b768d1 fixed a bug in collectFromPolicies
  • 56e8215 updated 'resource-routing-bridge/router-peer-change refreshes policy sources' test to expect router peer among changed peer ids
  • 1205641 fixed test
  • d8e7f2e a couple of fixes

📊 Changes

4 files changed (+325 additions, -67 deletions)

View changed files

📝 management/server/affected_peers_coverage_test.go (+3 -7)
📝 management/server/affected_peers_test.go (+71 -33)
📝 management/server/affectedpeers/resolver.go (+73 -14)
📝 management/server/affectedpeers/resolver_test.go (+178 -13)

📄 Description

Describe your changes

In affected peer calculation, when walking policies of groups and peers, only use opposite sides of those policies; i.e. if a policy rule sources include the group, use the rule's destinations, and vice-versa. Similarly, if a rule's SourceResource matches a peer from the change set, use rule's DesstinationResource and vice-versa.

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Refactor

    • Improved how policy changes are analyzed to determine the affected peer and group impact, using directionally-derived extraction from policy rules for more accurate and deterministic results.
  • Tests

    • Reworked resolver unit tests to validate precise affected peer/group sets derived from policy source/destination direction rules, including expanded coverage for mixed resource types and allowlist edge cases.
    • Updated affected-peers coverage-matrix expectations and tightened assertions to compare exact included/excluded sets.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6526 **Author:** [@dmitri-netbird](https://github.com/dmitri-netbird) **Created:** 6/23/2026 **Status:** 🔄 Open **Base:** `main` ← **Head:** `dmitri-filter-policies-by-direction` --- ### 📝 Commits (7) - [`7873f33`](https://github.com/netbirdio/netbird/commit/7873f337df2ebc191c9f666a4bcb72577730f53d) when collecting group and peer IDs from policies, do so directionally - [`4c4434a`](https://github.com/netbirdio/netbird/commit/4c4434a8715c7d214fbbd37d57052c840fe475ad) fixed a few tests - [`33954ea`](https://github.com/netbirdio/netbird/commit/33954ea15e616b72499cf82ac450b8c07d8591c0) fixing tests + adding tests - [`9b768d1`](https://github.com/netbirdio/netbird/commit/9b768d17734133fb4df18c6ff742762704b1e03f) fixed a bug in collectFromPolicies - [`56e8215`](https://github.com/netbirdio/netbird/commit/56e8215ebe16ff354647fbb7c238a9e2de964dfa) updated 'resource-routing-bridge/router-peer-change refreshes policy sources' test to expect router peer among changed peer ids - [`1205641`](https://github.com/netbirdio/netbird/commit/1205641b44e795a4c8aef215d14244de37a04640) fixed test - [`d8e7f2e`](https://github.com/netbirdio/netbird/commit/d8e7f2e9e67167175d9ad75c05d1ea38e0919946) a couple of fixes ### 📊 Changes **4 files changed** (+325 additions, -67 deletions) <details> <summary>View changed files</summary> 📝 `management/server/affected_peers_coverage_test.go` (+3 -7) 📝 `management/server/affected_peers_test.go` (+71 -33) 📝 `management/server/affectedpeers/resolver.go` (+73 -14) 📝 `management/server/affectedpeers/resolver_test.go` (+178 -13) </details> ### 📄 Description ## Describe your changes In affected peer calculation, when walking policies of groups and peers, only use opposite sides of those policies; i.e. if a policy rule sources include the group, use the rule's destinations, and vice-versa. Similarly, if a rule's SourceResource matches a peer from the change set, use rule's DesstinationResource and vice-versa. ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [x] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [x] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved how policy changes are analyzed to determine the affected peer and group impact, using directionally-derived extraction from policy rules for more accurate and deterministic results. * **Tests** * Reworked resolver unit tests to validate precise affected peer/group sets derived from policy source/destination direction rules, including expanded coverage for mixed resource types and allowlist edge cases. * Updated affected-peers coverage-matrix expectations and tightened assertions to compare exact included/excluded sets. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:06:15 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#28378