From 00e98f1f92bcc85981c27f25aacf4c3632170482 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 31 Aug 2026 01:20:58 +0200 Subject: [PATCH] The vocabulary has no word for a unit that runs and exits Found by the firewall: every packet filtered as declared, and the machine reported as not doing what it was told, because the unit that loaded the rules had finished. Stated as a gap rather than worked around silently. --- 03-DESIGN/01-to-be/08-connectivity.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/03-DESIGN/01-to-be/08-connectivity.md b/03-DESIGN/01-to-be/08-connectivity.md index bddb35b..5404819 100644 --- a/03-DESIGN/01-to-be/08-connectivity.md +++ b/03-DESIGN/01-to-be/08-connectivity.md @@ -317,6 +317,18 @@ something: | **flush the ruleset** when loading | that empties every table on the machine, the runtime's among them. Only the mesh's own table is replaced, and it is declared empty first so the replacement works on a machine loading one for the first time | | carry a **command to load itself** | the link may not carry an action ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)). A service is declared to reflect the file instead, so replacing it restarts what loads it — the shape that rule leaves, used here for the first time for its real purpose | +**A module that wants a rule set brings the unit that loads it.** Found the hard way: the unit a +distribution packages for nftables runs, applies the rules and exits, so it is neither running nor +stopped — and a host asked for a service that is "running" reports, quite correctly, that it is +stopped. Every packet was filtered exactly as declared and the machine was marked as not doing what +it was told. + +**The vocabulary has no word for "ran, did its job, and exited"**, and that is a real gap rather +than a wording problem: the whole class of configuration-applying units — packet filters, sysctl, +tmpfiles — is shaped that way. Until there is one, a module ships a unit that stays, which is also +the better shape: how a machine enforces rules is a fact about the machine, and the mesh has no +business depending on what a distribution happens to package. + **One thing is derived from what is assigned and not yet from the overlay's shape**, and it is stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound connections from every node at other sites; a node that is not a hub dials out and needs nothing