Merge pull request 'Cite hq ADR 0170, not 0169: the firewall seat's record was renumbered' (#219) from fix/adr-0170-cited into main
This commit was merged in pull request #219.
This commit is contained in:
@@ -14,7 +14,7 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \
|
|||||||
FROM ${RUNTIME_BASE}
|
FROM ${RUNTIME_BASE}
|
||||||
# The filter's own tools: nft for the machine's ruleset and the mesh's table, iptables for the
|
# The filter's own tools: nft for the machine's ruleset and the mesh's table, iptables for the
|
||||||
# legacy filter and the tables iptables-nft manages — a predecessor's rules live there (ADR 0168).
|
# legacy filter and the tables iptables-nft manages — a predecessor's rules live there (ADR 0168).
|
||||||
# The container runs on the machine's network with NET_ADMIN (ADR 0169), so these act on the
|
# The container runs on the machine's network with NET_ADMIN (ADR 0170), so these act on the
|
||||||
# machine's packet filter, not on a namespace of their own.
|
# machine's packet filter, not on a namespace of their own.
|
||||||
RUN apt-get update \
|
RUN apt-get update \
|
||||||
&& apt-get install -y --no-install-recommends nftables iptables \
|
&& apt-get install -y --no-install-recommends nftables iptables \
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
// rule set from every module's `listens` and writes it to the filter file (ADR 0045); the module
|
// rule set from every module's `listens` and writes it to the filter file (ADR 0045); the module
|
||||||
// loads it through its own unit. This code reads the filter back as the machine enforces it, reloads
|
// loads it through its own unit. This code reads the filter back as the machine enforces it, reloads
|
||||||
// the mesh's own table, and removes one thing the mesh did not write when the operator names it
|
// the mesh's own table, and removes one thing the mesh did not write when the operator names it
|
||||||
// (ADR 0168, ADR 0169) — the seat's three verbs, over the machine's own tools.
|
// (ADR 0168, ADR 0170) — the seat's three verbs, over the machine's own tools.
|
||||||
|
|
||||||
import { execFile } from "node:child_process";
|
import { execFile } from "node:child_process";
|
||||||
import { promisify } from "node:util";
|
import { promisify } from "node:util";
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "@novox/module-nftables",
|
"name": "@novox/module-nftables",
|
||||||
"version": "0.1.0",
|
"version": "0.1.0",
|
||||||
"description": "nftables — loads the mesh's packet filter and holds the node-packet-filter seat: its verbs rules, reload and remove (novox/hq ADR 0045, ADR 0169).",
|
"description": "nftables — loads the mesh's packet filter and holds the node-packet-filter seat: its verbs rules, reload and remove (novox/hq ADR 0045, ADR 0170).",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"private": true,
|
"private": true,
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
// The packet filter's tools: the node-packet-filter seat's three verbs — what the machine enforces,
|
// The packet filter's tools: the node-packet-filter seat's three verbs — what the machine enforces,
|
||||||
// reload the mesh's own, remove one thing the mesh did not write — and the module's own reading of
|
// reload the mesh's own, remove one thing the mesh did not write — and the module's own reading of
|
||||||
// the mesh's table (novox/hq ADR 0045, ADR 0168, ADR 0169).
|
// the mesh's table (novox/hq ADR 0045, ADR 0168, ADR 0170).
|
||||||
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
|
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
|
||||||
import { FirewallClient } from "../client.js";
|
import { FirewallClient } from "../client.js";
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user