Issue 047 — and the half that runs the other way #42

Merged
jschoubben merged 1 commits from issue/047-the-other-half into main 2026-09-14 13:09:37 +00:00
@@ -51,6 +51,33 @@ firewall that is up and dropping by default.
That is the worst shape a security fault can take: the mechanism is present, it reports success, and That is the worst shape a security fault can take: the mechanism is present, it reports success, and
the thing it is believed to be doing is not the thing it does. the thing it is believed to be doing is not the thing it does.
## The other half, which runs the opposite way
The section above is about ports the firewall **cannot close**. There is a matching fault about
ports it **does** close and should not, and together they are worse than either alone.
The rules are computed from what modules declare they listen on. During a migration a mesh knows
about almost nothing — the services are still running under the system being replaced — so it opens
almost nothing. Anything listening **on the host** rather than in a container is then dropped.
**Including ssh.** No module in the catalogue declares an ssh port, and the generator has no
built-in allowance for one. So the ruleset loaded on a machine that has not been told otherwise
accepts established connections, loopback and ping, and refuses every new ssh connection.
The session doing the loading survives, because established connections are accepted. It survives
until it drops. On a machine reached over the network that is the difference between a mistake and
a journey to a rescue console.
So the two halves are:
| | what it does | consequence |
|---|---|---|
| container ports, published | cannot see them, does not filter | stay open, protection silently lost |
| host ports, undeclared | sees them, drops them | **ssh among them** |
The mesh gets no say over the ports most worth protecting, and full say over the one that must never
be closed by accident.
## How it would be checked ## How it would be checked
Two probes from another machine, against a port on the host and a published container port, before Two probes from another machine, against a port on the host and a published container port, before