State the one rule the derivation does not yet reach
A hub needs its overlay port open and a node that is not a hub does not, and they are the same module — so listens, a static manifest field, cannot express it while the overlay module's resources are computed per node. Written down rather than left as an oversight for whoever first puts a firewall on a hub.
This commit is contained in:
@@ -317,6 +317,18 @@ something:
|
||||
| **flush the ruleset** when loading | that empties every table on the machine, the runtime's among them. Only the mesh's own table is replaced, and it is declared empty first so the replacement works on a machine loading one for the first time |
|
||||
| carry a **command to load itself** | the link may not carry an action ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)). A service is declared to reflect the file instead, so replacing it restarts what loads it — the shape that rule leaves, used here for the first time for its real purpose |
|
||||
|
||||
**One thing is derived from what is assigned and not yet from the overlay's shape**, and it is
|
||||
stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound
|
||||
connections from every node at other sites; a node that is not a hub dials out and needs nothing
|
||||
open, because a reply to a flow it started is already accepted. So the two want different rules on
|
||||
an identical module — and `listens` is a static field on a manifest, while the overlay module's
|
||||
resources are computed per node.
|
||||
|
||||
A machine that is not a hub is therefore correct today, and **a hub would have its own port closed
|
||||
by a rule set derived this way.** The fix is that a computed module contributes listens the way it
|
||||
contributes resources; until it exists, the firewall belongs on machines that are not hubs, and
|
||||
this paragraph is the reason rather than an oversight to find later.
|
||||
|
||||
**And it is enforced, which is what separates this from `scope:`.** Checked on two real machines:
|
||||
two ports opened, one declared, and from the other machine the declared one answers and the
|
||||
undeclared one does not — then the module is removed and the port closes with nobody editing a
|
||||
|
||||
Reference in New Issue
Block a user