diff --git a/03-DESIGN/01-to-be/08-connectivity.md b/03-DESIGN/01-to-be/08-connectivity.md index bddb35b..5404819 100644 --- a/03-DESIGN/01-to-be/08-connectivity.md +++ b/03-DESIGN/01-to-be/08-connectivity.md @@ -317,6 +317,18 @@ something: | **flush the ruleset** when loading | that empties every table on the machine, the runtime's among them. Only the mesh's own table is replaced, and it is declared empty first so the replacement works on a machine loading one for the first time | | carry a **command to load itself** | the link may not carry an action ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)). A service is declared to reflect the file instead, so replacing it restarts what loads it — the shape that rule leaves, used here for the first time for its real purpose | +**A module that wants a rule set brings the unit that loads it.** Found the hard way: the unit a +distribution packages for nftables runs, applies the rules and exits, so it is neither running nor +stopped — and a host asked for a service that is "running" reports, quite correctly, that it is +stopped. Every packet was filtered exactly as declared and the machine was marked as not doing what +it was told. + +**The vocabulary has no word for "ran, did its job, and exited"**, and that is a real gap rather +than a wording problem: the whole class of configuration-applying units — packet filters, sysctl, +tmpfiles — is shaped that way. Until there is one, a module ships a unit that stays, which is also +the better shape: how a machine enforces rules is a fact about the machine, and the mesh has no +business depending on what a distribution happens to package. + **One thing is derived from what is assigned and not yet from the overlay's shape**, and it is stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound connections from every node at other sites; a node that is not a hub dials out and needs nothing