diff --git a/modules/nftables/Dockerfile b/modules/nftables/Dockerfile index 2c4a8c2..8f26e09 100644 --- a/modules/nftables/Dockerfile +++ b/modules/nftables/Dockerfile @@ -14,7 +14,7 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ FROM ${RUNTIME_BASE} # The filter's own tools: nft for the machine's ruleset and the mesh's table, iptables for the # legacy filter and the tables iptables-nft manages — a predecessor's rules live there (ADR 0168). -# The container runs on the machine's network with NET_ADMIN (ADR 0169), so these act on the +# The container runs on the machine's network with NET_ADMIN (ADR 0170), so these act on the # machine's packet filter, not on a namespace of their own. RUN apt-get update \ && apt-get install -y --no-install-recommends nftables iptables \ diff --git a/modules/nftables/client.ts b/modules/nftables/client.ts index fd283d2..b8e7c3d 100644 --- a/modules/nftables/client.ts +++ b/modules/nftables/client.ts @@ -2,7 +2,7 @@ // rule set from every module's `listens` and writes it to the filter file (ADR 0045); the module // loads it through its own unit. This code reads the filter back as the machine enforces it, reloads // the mesh's own table, and removes one thing the mesh did not write when the operator names it -// (ADR 0168, ADR 0169) — the seat's three verbs, over the machine's own tools. +// (ADR 0168, ADR 0170) — the seat's three verbs, over the machine's own tools. import { execFile } from "node:child_process"; import { promisify } from "node:util"; diff --git a/modules/nftables/package.json b/modules/nftables/package.json index d1ca3f3..67ae14c 100644 --- a/modules/nftables/package.json +++ b/modules/nftables/package.json @@ -1,7 +1,7 @@ { "name": "@novox/module-nftables", "version": "0.1.0", - "description": "nftables — loads the mesh's packet filter and holds the node-packet-filter seat: its verbs rules, reload and remove (novox/hq ADR 0045, ADR 0169).", + "description": "nftables — loads the mesh's packet filter and holds the node-packet-filter seat: its verbs rules, reload and remove (novox/hq ADR 0045, ADR 0170).", "type": "module", "private": true, "scripts": { diff --git a/modules/nftables/tools/index.ts b/modules/nftables/tools/index.ts index c921ec9..8a32bd0 100644 --- a/modules/nftables/tools/index.ts +++ b/modules/nftables/tools/index.ts @@ -1,6 +1,6 @@ // The packet filter's tools: the node-packet-filter seat's three verbs — what the machine enforces, // reload the mesh's own, remove one thing the mesh did not write — and the module's own reading of -// the mesh's table (novox/hq ADR 0045, ADR 0168, ADR 0169). +// the mesh's table (novox/hq ADR 0045, ADR 0168, ADR 0170). import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools"; import { FirewallClient } from "../client.js";