ADR 0100: the machine's own traffic is known by its interface, not its source address

This commit is contained in:
2026-09-22 16:35:25 +02:00
parent 37252f9c3e
commit 3d4ab23830
2 changed files with 4 additions and 2 deletions
@@ -118,7 +118,8 @@ everything by default and holds nothing but refusals, and the two ports it refus
foundation's own, checked free at genesis, so it cannot close anything the machine serves; it is foundation's own, checked free at genesis, so it cannot close anything the machine serves; it is
the mesh's, so the found firewall reloading does not touch it. It refuses the store's port and the the mesh's, so the found firewall reloading does not touch it. It refuses the store's port and the
broker's management port except from the private network and from the machine itself — its broker's management port except from the private network and from the machine itself — its
loopback and the container runtime's own networks — at the prerouting hook, ahead of the runtime's loopback and the container runtime's own networks, known by the interface a packet arrives on and
never by its source address alone — at the prerouting hook, ahead of the runtime's
destination translation, so it matches the port the packet was sent to, for both address destination translation, so it matches the port the packet was sent to, for both address
families. The bus and the registry stay reachable from anywhere, as a node families. The bus and the registry stay reachable from anywhere, as a node
enrols over the bus and pulls from the registry before it has a private-network address enrols over the bus and pulls from the registry before it has a private-network address
+2 -1
View File
@@ -553,7 +553,8 @@ other resource. **The mesh guards its own ports in a table of its own that only
passing everything by default and holding nothing but refusals of the foundation's own two ports, passing everything by default and holding nothing but refusals of the foundation's own two ports,
checked free at genesis, so it cannot close what the machine serves, and the found firewall's checked free at genesis, so it cannot close what the machine serves, and the found firewall's
reload does not touch it. It refuses the store's port and the broker's management port except from reload does not touch it. It refuses the store's port and the broker's management port except from
the private network and the machine itself — loopback and the container runtime's networks — at the private network and the machine itself — loopback and the container runtime's networks, known by the interface a packet arrives on, never by
its source address alone — at
the prerouting hook, before the container runtime redirects the packet, so it matches the port the the prerouting hook, before the container runtime redirects the packet, so it matches the port the
packet was sent to, for both address families; the packet was sent to, for both address families; the
bus, the registry and the hub's port stay reachable from anywhere, as a node enrols and pulls bus, the registry and the hub's port stay reachable from anywhere, as a node enrols and pulls