The packet filter's tools are a bundle the node's runtime serves; its container goes (hq to-be 38 WP4)
nftables drops its container, NET_ADMIN, the container-runtime capability, the runtime base images and the Dockerfile; its tools are declared as a TypeScript bundle the toolchain compiles and node-tools loads on every node. The runtime runs as the operator's account, so the tool runs the filter's commands through sudo without a prompt when it is not root (ADR 0175 §4); the filter file is the path the manifest's filtering names, no container env carrying it.
This commit is contained in:
@@ -4,7 +4,7 @@
|
||||
// and the same in an iptables-nft table. It refuses what is not the operator's to remove.
|
||||
import { test } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
import { FirewallClient, chainsJumpingTo, type Runner } from "../client.ts";
|
||||
import { FirewallClient, chainsJumpingTo, escalated, type Runner } from "../client.ts";
|
||||
|
||||
const legacy = [
|
||||
"-P INPUT ACCEPT", "-P FORWARD DROP", "-P OUTPUT ACCEPT",
|
||||
@@ -72,3 +72,9 @@ test("which chains jump to a target is read from a listing", () => {
|
||||
const listing = "table ip6 own {\n\tchain a {\n\t\tjump deny\n\t}\n\tchain b {\n\t\tgoto deny\n\t}\n\tchain deny {\n\t\tdrop\n\t}\n}\n";
|
||||
assert.deepEqual(chainsJumpingTo(listing, "deny"), ["a", "b"]);
|
||||
});
|
||||
|
||||
test("the filter's commands run as given by root and through sudo without a prompt by anyone else", () => {
|
||||
assert.deepEqual(escalated("nft", ["list", "ruleset"], 0), ["nft", ["list", "ruleset"]]);
|
||||
assert.deepEqual(escalated("nft", ["-f", "/etc/nftables.conf"], 1000), ["sudo", ["-n", "nft", "-f", "/etc/nftables.conf"]]);
|
||||
assert.deepEqual(escalated("iptables-legacy", ["-S"], undefined), ["sudo", ["-n", "iptables-legacy", "-S"]]);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user