types: detect policy change on user identity and exit routes

Updates #3417

(cherry picked from commit 905ab92fe0)
This commit is contained in:
Kristoffer Dalby
2026-09-09 14:36:56 +00:00
parent bc5b9d56b2
commit 4411264ef9
2 changed files with 170 additions and 2 deletions
+15 -2
View File
@@ -1179,9 +1179,18 @@ func equalPrefixesUnordered(a, b []netip.Prefix) bool {
// HasPolicyChange reports whether the node has changes that affect
// policy evaluation. Includes approved subnet routes because they act
// as source identity in [Node.CanAccess] for subnet-to-subnet ACLs.
// as source identity in [Node.CanAccess] for subnet-to-subnet ACLs,
// and enabled exit routes because autogroup:internet and exit-node
// reduction depend on which exit nodes are advertised-and-approved.
func (nv NodeView) HasPolicyChange(other NodeView) bool {
if nv.UserID() != other.UserID() {
if nv.TypedUserID() != other.TypedUserID() {
return true
}
// The policy resolves ownership through the loaded association, so
// compare it as well as the raw foreign key.
if nv.User().Valid() != other.User().Valid() ||
(nv.User().Valid() && nv.User().ID() != other.User().ID()) {
return true
}
@@ -1197,6 +1206,10 @@ func (nv NodeView) HasPolicyChange(other NodeView) bool {
return true
}
if !equalPrefixesUnordered(nv.ExitRoutes(), other.ExitRoutes()) {
return true
}
return false
}