Tech debt noted while reviewing #95 (which added ~42 lines there for map sizing + starting the step tracker — localized and fail-soft, but on top of an already large file).
StartCargoWall carries the whole daemon bring-up in one function: config/policy load, logging, DNS proxy, iptables redirect, Docker DNS interception, BPF load and attach, firewall programming, existing-connection gating, sudo lockdown, readiness, and teardown defers. The ordering between those stages is genuinely load-bearing (maps must be fully programmed before TC attaches; existing connections are re-scanned just before attach; teardown must unwind in reverse), which is exactly why it deserves named stages rather than one long body.
Suggested direction — extract cohesive phases with explicit inputs/outputs, keeping the current order and defer semantics:
- BPF load + attach (including the step-map sizing and cgroup/tracepoint attaches)
- DNS proxy + redirect setup
- Firewall programming + existing-connection gating
- Lockdown + readiness + teardown registration
Behavior-preserving refactor; the value is that the attach-ordering invariants become visible in the structure instead of only in comments. Worth doing before the container work in #106 adds another attach path.
Tech debt noted while reviewing #95 (which added ~42 lines there for map sizing + starting the step tracker — localized and fail-soft, but on top of an already large file).
StartCargoWallcarries the whole daemon bring-up in one function: config/policy load, logging, DNS proxy, iptables redirect, Docker DNS interception, BPF load and attach, firewall programming, existing-connection gating, sudo lockdown, readiness, and teardown defers. The ordering between those stages is genuinely load-bearing (maps must be fully programmed before TC attaches; existing connections are re-scanned just before attach; teardown must unwind in reverse), which is exactly why it deserves named stages rather than one long body.Suggested direction — extract cohesive phases with explicit inputs/outputs, keeping the current order and defer semantics:
Behavior-preserving refactor; the value is that the attach-ordering invariants become visible in the structure instead of only in comments. Worth doing before the container work in #106 adds another attach path.