firewall: the module that applies the mesh-computed packet filter (ADR 0050)

The missing applier. mesh-control already derives a node's whole nftables rule
set from the union of its modules' listens and writes it to /etc/nftables.conf;
this module declares filtering:{into} to receive it and loads it — the nftables
service, reloaded on 'filtering' whenever the rules change. A firewall_rules
tool reads the live table so a declared scope can be checked against what is
really enforced. Closes the loop from listens.from to a packet actually dropped.
Manifest parses; tool typechecks.
This commit is contained in:
2026-09-04 20:52:26 +02:00
parent d59649de0a
commit 0e102dd350
5 changed files with 102 additions and 0 deletions
+14
View File
@@ -0,0 +1,14 @@
{
"name": "@novox/module-firewall",
"version": "0.1.0",
"description": "firewall — applies the mesh-computed packet filter (ADR 0050). Its diagnostic tool lives here.
"type": "module",
"private": true,
"dependencies": {
"@novox/mesh-sdk": "^0.1.0"
},
"devDependencies": {
"@types/node": "^22.0.0",
"typescript": "^5.6.0"
}
}