55 lines
2.9 KiB
Markdown
55 lines
2.9 KiB
Markdown
---
|
|
status: resolved
|
|
opened: 2026-10-02
|
|
located-in: [mesh-controller internal/catalogue/filtering.go (AsNftables: the forward chain has no rule for the mesh passing through, so a relayed packet is judged by this machine's own published ports)]
|
|
fixed-by: mesh-controller PR 209 (the forward chain relays what comes in and goes out on the tunnel), live 2026-10-02
|
|
amended-design: []
|
|
---
|
|
|
|
# 196 — The hub relays the mesh only on the ports it publishes for itself
|
|
|
|
## What was observed
|
|
|
|
A sweep of every listening port on every machine, from every other machine, on 2026-10-02. Two home
|
|
machines, neither of which can be dialled, reach a third home machine through the hub, as
|
|
[ADR 0007](../../02-DECISIONS/0007-connectivity.md) says every path between machines that are not
|
|
co-located does.
|
|
|
|
From either of the two, the third answered on **17 of its 55** listening ports over the mesh. The hub
|
|
itself, probing the same machine directly, reached all the ports that machine's rules open to the mesh.
|
|
The result was the same at 40 probes in parallel and at 4, so it was not load.
|
|
|
|
The 17 were not a property of the target. They were exactly the ports **the hub** publishes for its own
|
|
containers: ssh, the proxy's two, and the hub's own block of published ports. A capture on the target
|
|
during one probe to a port that answered and one that did not:
|
|
|
|
- the answering one: the SYN arrives on the tunnel, reaches the container, and the reply leaves by the
|
|
tunnel;
|
|
- the other: nothing arrives at all, on any interface.
|
|
|
|
## Why it matters
|
|
|
|
**ADR 0007's hub carries every path between machines that are not co-located, and the filter breaks
|
|
that path without saying so.** Whether one home machine can reach a service on another depends on
|
|
whether the hub happens to publish the same port number for something of its own. Adding or removing
|
|
a module on the hub silently opens or closes paths between two other machines that it has nothing to
|
|
do with.
|
|
|
|
It also hid behind another fault. A missing placement made the same pair look disconnected earlier the
|
|
same day, and that explanation fit well enough that the per-port pattern was not looked for.
|
|
|
|
## Open questions
|
|
|
|
- The relaying rule accepts what comes in on the tunnel and leaves on it, and leaves judging to the
|
|
machine it is for. Should the hub also restrict relayed traffic to what that machine opens to the
|
|
mesh? That would duplicate the target's rules on the hub.
|
|
- No test raises two machines behind a hub and checks a port between them that the hub does not
|
|
publish. The lab's beds have one machine per site.
|
|
|
|
## Resolved (2026-10-02)
|
|
|
|
Live on all four machines after one push each. The same sweep, from both home machines to the third
|
|
over the mesh: 45 of 55 ports answer, the same 45 the hub reaches directly. The 9 that do not are
|
|
ports the target opens to nobody on the mesh, and one is refused because it listens only on a LAN
|
|
address. Nothing answers that the target's rules do not open.
|