Issues 140 and 141: an endpoint's reach, and a forward chain that does not follow the modules #169

Merged
mesh-admin merged 1 commits from issue/140-endpoint-reach-and-141-forward-chain into main 2026-09-28 20:58:03 +00:00
Contributor

Two faults found while preparing the control-node's convergence, the last machine still
running the packet filter it had before the mesh.

140 — an endpoint's reach is declared nowhere. A module has ports, and separately it has
routes. Nothing binds a port to a name to a certificate, so the filter, the proxy's names and
the certificate authority each settle reach on their own: a per-node setting overrides a port's
source and is read by the filter alone, while the proxy composes both a public and an internal
name for every route it is given and obtains a certificate for each from a different authority.
Measured: an identity provider carries a 90-day public certificate and a 24-hour internal one,
neither asked for by any assignment. "This endpoint must not be public" cannot be written, so it
is enforced by nothing — and the open certificate questions (which authority, expiry, revocation)
cannot be answered until it can be.

141 — the forward chain follows constants, not the modules. It allows two ranges named in the
control plane's source plus a list a person types since ADR 0137. The machine measured hosts 21
container networks; six fall outside the constant and would have lost their guests on the flip.
Four of those six are networks the mesh's own modules declare and the host created; two are
predecessor leftovers. Any range wide enough to keep the four forwards the two as well. ADR 0137
rejected deriving this from what the machine reports, correctly — but deriving it from the
declaration has neither objection it raised: the set is known before the network exists, and it
cannot widen itself.

Both end in open questions; neither proposes a fix. Diagnosis and graduation are separate steps.

Two faults found while preparing the control-node's convergence, the last machine still running the packet filter it had before the mesh. **140 — an endpoint's reach is declared nowhere.** A module has ports, and separately it has routes. Nothing binds a port to a name to a certificate, so the filter, the proxy's names and the certificate authority each settle reach on their own: a per-node setting overrides a port's source and is read by the filter alone, while the proxy composes both a public and an internal name for every route it is given and obtains a certificate for each from a different authority. Measured: an identity provider carries a 90-day public certificate and a 24-hour internal one, neither asked for by any assignment. "This endpoint must not be public" cannot be written, so it is enforced by nothing — and the open certificate questions (which authority, expiry, revocation) cannot be answered until it can be. **141 — the forward chain follows constants, not the modules.** It allows two ranges named in the control plane's source plus a list a person types since ADR 0137. The machine measured hosts 21 container networks; six fall outside the constant and would have lost their guests on the flip. Four of those six are networks the mesh's own modules declare and the host created; two are predecessor leftovers. Any range wide enough to keep the four forwards the two as well. ADR 0137 rejected deriving this from *what the machine reports*, correctly — but deriving it from the *declaration* has neither objection it raised: the set is known before the network exists, and it cannot widen itself. Both end in open questions; neither proposes a fix. Diagnosis and graduation are separate steps.
mesh-admin added 1 commit 2026-09-28 20:58:02 +00:00
Found preparing the control-node's convergence. Reach is settled independently by
the filter, the proxy's names and the certificate authority, so "this must not be
public" cannot be written and a public certificate is obtained regardless. And the
forward chain allows two hardcoded ranges plus a typed list, though the mesh
already knows which networks exist because its own modules declared them — a range
wide enough to keep four of them would have forwarded two predecessor leftovers too.
mesh-admin merged commit 2126e7b2cb into main 2026-09-28 20:58:03 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#169