ADR 0140: the filter constrains what arrives from outside #171

Merged
mesh-admin merged 1 commits from decision/0140-filter-constrains-what-arrives-from-outside into main 2026-09-28 21:32:10 +00:00
Contributor

Supersedes ADR 0137 and ADR 0139 with one rule, after reading what a converged machine
actually loads:

policy drop
ct state established,related accept
ip saddr 172.16.0.0/12 accept      <- constants in this repo's code
ip saddr 192.168.128.0/17 accept
ip saddr 10.0.0.0/8 accept         <- and the list 0137 made typeable
ip saddr 192.168.16.0/20 accept
... four more

The chain blocks everything passing through the machine and then allows the machine's own
containers back in by listing their address ranges. 0137 existed to make that list typeable
after the flip had already cut a workstation off; 0139 tried to generate the same list from
the modules and put half the rule set on the machine to do it. Three records, one list, and
the list is the mistake — because the mesh has no position on a container reaching outward.
That is not a port being opened to anybody.

So: the filter constrains traffic arriving from outside the machine and says nothing about
traffic that did not. A machine reports which of its links face outside — one fact, like the
firewall kind and the tunnel it already reports, not a setting and not a list. It does not
change when a module is added or removed. A machine that reports no outward link is sent no
filter and keeps the one it has, because a rule around a nameless link is a rule set that does
not load.

Ports keep following the modules exactly as before. Assign a module and the port its assignment
says it reaches on opens; nothing about a network is said anywhere.

Consequences: the two constants and node networks are removed, with everything any machine was
told through it — the workstation's five ranges and the laptop's one are deleted, not migrated.
Test beds stop being a special case. The new fact travels in the report, so machines report before
the control plane depends on it.

Also here: the records check now allows one record to supersede several, which it could not
express, and no longer requires a withdrawn record's own citations to be live — a superseded
record instructs nobody, and rewriting its lineage is what the immutability rule forbids.

Design 08-connectivity §4 rewritten accordingly. Issue 141 records that the answer was "no list",
not "a better list". records, cycle and index pass.

Supersedes ADR 0137 and ADR 0139 with one rule, after reading what a converged machine actually loads: ``` policy drop ct state established,related accept ip saddr 172.16.0.0/12 accept <- constants in this repo's code ip saddr 192.168.128.0/17 accept ip saddr 10.0.0.0/8 accept <- and the list 0137 made typeable ip saddr 192.168.16.0/20 accept ... four more ``` The chain blocks everything passing through the machine and then allows the machine's own containers back in by listing their address ranges. 0137 existed to make that list typeable after the flip had already cut a workstation off; 0139 tried to generate the same list from the modules and put half the rule set on the machine to do it. Three records, one list, and the list is the mistake — because the mesh has no position on a container reaching outward. That is not a port being opened to anybody. So: the filter constrains traffic arriving from **outside** the machine and says nothing about traffic that did not. A machine reports which of its links face outside — one fact, like the firewall kind and the tunnel it already reports, not a setting and not a list. It does not change when a module is added or removed. A machine that reports no outward link is sent no filter and keeps the one it has, because a rule around a nameless link is a rule set that does not load. Ports keep following the modules exactly as before. Assign a module and the port its assignment says it reaches on opens; nothing about a network is said anywhere. Consequences: the two constants and `node networks` are removed, with everything any machine was told through it — the workstation's five ranges and the laptop's one are deleted, not migrated. Test beds stop being a special case. The new fact travels in the report, so machines report before the control plane depends on it. Also here: the records check now allows one record to supersede several, which it could not express, and no longer requires a withdrawn record's own citations to be live — a superseded record instructs nobody, and rewriting its lineage is what the immutability rule forbids. Design `08-connectivity` §4 rewritten accordingly. Issue 141 records that the answer was "no list", not "a better list". records, cycle and index pass.
mesh-admin added 1 commit 2026-09-28 21:32:09 +00:00
Reading a converged machine's rendered rules showed the cause: the chain blocks
everything passing through and then allows the machine's own containers back by
listing their address ranges. 0137 made that list typeable and 0139 tried to
generate it; both refined a list that should not exist, because the mesh has no
position on a container reaching outward. Constrain what arrives from outside,
allow what did not, and let the machine report which links face outside — one
fact instead of a list. Ports keep following the modules unchanged.

The records check now allows one record to supersede several, and stops
requiring a withdrawn record's own citations to be live.
mesh-admin merged commit c6f86ae935 into main 2026-09-28 21:32:10 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#171