From 261064ec63de40bde481a8ef6c17dcd69f525d81 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 14 Sep 2026 15:09:20 +0200 Subject: [PATCH] =?UTF-8?q?Issue=20047=20=E2=80=94=20and=20the=20half=20th?= =?UTF-8?q?at=20runs=20the=20other=20way?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The report covered ports the firewall cannot close. The matching fault is ports it does close and should not: rules come from what modules declare, a migrating mesh knows about almost nothing, and anything listening on the host is dropped. No module declares an ssh port and the generator has no allowance for one. The session that loads the rules survives on conntrack until it drops, and then the machine is reached from a rescue console. --- .../00-report.md | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/04-ISSUES/047-the-firewall-does-not-cover-published-container-ports/00-report.md b/04-ISSUES/047-the-firewall-does-not-cover-published-container-ports/00-report.md index d72f232..f3f27e0 100644 --- a/04-ISSUES/047-the-firewall-does-not-cover-published-container-ports/00-report.md +++ b/04-ISSUES/047-the-firewall-does-not-cover-published-container-ports/00-report.md @@ -51,6 +51,33 @@ firewall that is up and dropping by default. That is the worst shape a security fault can take: the mechanism is present, it reports success, and the thing it is believed to be doing is not the thing it does. +## The other half, which runs the opposite way + +The section above is about ports the firewall **cannot close**. There is a matching fault about +ports it **does** close and should not, and together they are worse than either alone. + +The rules are computed from what modules declare they listen on. During a migration a mesh knows +about almost nothing — the services are still running under the system being replaced — so it opens +almost nothing. Anything listening **on the host** rather than in a container is then dropped. + +**Including ssh.** No module in the catalogue declares an ssh port, and the generator has no +built-in allowance for one. So the ruleset loaded on a machine that has not been told otherwise +accepts established connections, loopback and ping, and refuses every new ssh connection. + +The session doing the loading survives, because established connections are accepted. It survives +until it drops. On a machine reached over the network that is the difference between a mistake and +a journey to a rescue console. + +So the two halves are: + +| | what it does | consequence | +|---|---|---| +| container ports, published | cannot see them, does not filter | stay open, protection silently lost | +| host ports, undeclared | sees them, drops them | **ssh among them** | + +The mesh gets no say over the ports most worth protecting, and full say over the one that must never +be closed by accident. + ## How it would be checked Two probes from another machine, against a port on the host and a published container port, before -- 2.54.0