diff --git a/03-DESIGN/01-to-be/08-connectivity.md b/03-DESIGN/01-to-be/08-connectivity.md index dc9fb91..bddb35b 100644 --- a/03-DESIGN/01-to-be/08-connectivity.md +++ b/03-DESIGN/01-to-be/08-connectivity.md @@ -317,6 +317,18 @@ something: | **flush the ruleset** when loading | that empties every table on the machine, the runtime's among them. Only the mesh's own table is replaced, and it is declared empty first so the replacement works on a machine loading one for the first time | | carry a **command to load itself** | the link may not carry an action ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)). A service is declared to reflect the file instead, so replacing it restarts what loads it — the shape that rule leaves, used here for the first time for its real purpose | +**One thing is derived from what is assigned and not yet from the overlay's shape**, and it is +stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound +connections from every node at other sites; a node that is not a hub dials out and needs nothing +open, because a reply to a flow it started is already accepted. So the two want different rules on +an identical module — and `listens` is a static field on a manifest, while the overlay module's +resources are computed per node. + +A machine that is not a hub is therefore correct today, and **a hub would have its own port closed +by a rule set derived this way.** The fix is that a computed module contributes listens the way it +contributes resources; until it exists, the firewall belongs on machines that are not hubs, and +this paragraph is the reason rather than an oversight to find later. + **And it is enforced, which is what separates this from `scope:`.** Checked on two real machines: two ports opened, one declared, and from the other machine the declared one answers and the undeclared one does not — then the module is removed and the port closes with nobody editing a