From c3730b9a23f8d405a0661e81886c1d171ca227be Mon Sep 17 00:00:00 2001 From: jochens Date: Tue, 29 Sep 2026 23:06:08 +0200 Subject: [PATCH] Issue 150: a machine's own network is not a reach ADR 0138's reach is internal, public or both. ace's LAN devices (an IoT switch on mosquitto, unifi access points, plex clients) are none of them; the only reach that admits them is public, which states the wrong thing and opens the port to the internet on any machine with a public address. --- .../00-report.md | 42 +++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 04-ISSUES/150-a-machines-own-network-is-not-a-reach/00-report.md diff --git a/04-ISSUES/150-a-machines-own-network-is-not-a-reach/00-report.md b/04-ISSUES/150-a-machines-own-network-is-not-a-reach/00-report.md new file mode 100644 index 0000000..c49970f --- /dev/null +++ b/04-ISSUES/150-a-machines-own-network-is-not-a-reach/00-report.md @@ -0,0 +1,42 @@ +--- +status: open +opened: 2026-09-29 +located-in: + - hq 02-DECISIONS/0138 (reach: internal | public | both) + - mesh-controller internal/catalogue/filtering.go (Reaches) +fixed-by: +amended-design: +--- + +# 150 — A machine's own network is not a reach + +## What was observed + +Preparing ace's modules. ace sits on a home network (192.168.1.0/24) behind a router, and several of +its services are reached **from that network by devices that will never be mesh machines**: + +- mosquitto `1883` — an IoT light switch (`sonoff-office-light-switch`) and home-assistant; +- unifi `8080`/`3478 udp`/`10001 udp` — the access points' inform, STUN and discovery; +- plex `32400` — LAN streaming clients (three connected at survey time); +- home-assistant `8123`, and the resolver on the LAN address. + +ADR 0138 gives an endpoint's reach as `internal` (the private overlay), `public` (anywhere) or `both`. +None of them says *this machine's own network*. The predecessor could: its unifi manifest opened +inform/STUN/discovery `from: 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12`. + +## Consequence + +The only reach that includes a LAN device is `public`. While ace is adopted that is harmless — its +own firewall stays and admits the LAN — and behind NAT "anywhere" happens to mean the LAN. But: + +- it states the wrong thing: an operator reading `reach: public` on an IoT broker believes it is on + the internet, and a router port-forward added later for something else makes it so; +- at `converge ace`, the mesh's filter is the sum of what it listens on (ADR 0045). An endpoint left + `internal` cuts every LAN device off at the flip; one set `public` opens it to the internet on any + machine with a public address. + +## What would be right (for diagnosis) + +A reach — or a source — that means the networks the machine is directly attached to (its uplink's +subnets, as the machine reports them), so a LAN-only service is declared as exactly that and the +filter can admit it without admitting the internet.