Files
hq/04-ISSUES/196-the-hub-relays-only-the-ports-it-publishes-itself/00-report.md
T

2.9 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
resolved 2026-10-02
mesh-controller internal/catalogue/filtering.go (AsNftables
the forward chain has no rule for the mesh passing through
so a relayed packet is judged by this machine's own published ports)
mesh-controller PR 209 (the forward chain relays what comes in and goes out on the tunnel), live 2026-10-02

196 — The hub relays the mesh only on the ports it publishes for itself

What was observed

A sweep of every listening port on every machine, from every other machine, on 2026-10-02. Two home machines, neither of which can be dialled, reach a third home machine through the hub, as ADR 0007 says every path between machines that are not co-located does.

From either of the two, the third answered on 17 of its 55 listening ports over the mesh. The hub itself, probing the same machine directly, reached all the ports that machine's rules open to the mesh. The result was the same at 40 probes in parallel and at 4, so it was not load.

The 17 were not a property of the target. They were exactly the ports the hub publishes for its own containers: ssh, the proxy's two, and the hub's own block of published ports. A capture on the target during one probe to a port that answered and one that did not:

  • the answering one: the SYN arrives on the tunnel, reaches the container, and the reply leaves by the tunnel;
  • the other: nothing arrives at all, on any interface.

Why it matters

ADR 0007's hub carries every path between machines that are not co-located, and the filter breaks that path without saying so. Whether one home machine can reach a service on another depends on whether the hub happens to publish the same port number for something of its own. Adding or removing a module on the hub silently opens or closes paths between two other machines that it has nothing to do with.

It also hid behind another fault. A missing placement made the same pair look disconnected earlier the same day, and that explanation fit well enough that the per-port pattern was not looked for.

Open questions

  • The relaying rule accepts what comes in on the tunnel and leaves on it, and leaves judging to the machine it is for. Should the hub also restrict relayed traffic to what that machine opens to the mesh? That would duplicate the target's rules on the hub.
  • No test raises two machines behind a hub and checks a port between them that the hub does not publish. The lab's beds have one machine per site.

Resolved (2026-10-02)

Live on all four machines after one push each. The same sweep, from both home machines to the third over the mesh: 45 of 55 ports answer, the same 45 the hub reaches directly. The 9 that do not are ports the target opens to nobody on the mesh, and one is refused because it listens only on a LAN address. Nothing answers that the target's rules do not open.