nftables holds the node-packet-filter seat: rules, reload and remove, from a runtime with NET_ADMIN (hq ADR 0169)
The seat's three verbs over the machine's own tools: the filter as enforced (nftables and the legacy filter), the mesh's own table reloaded from its file, and one rule set the mesh did not write removed by the name the host reports it under (ADR 0168) — a predecessor's chain loses its jumps and goes, the runtime's user chain is emptied back to its return, a table of the machine's own goes whole; the mesh's tables, the runtime's chains, a built-in chain and an active found firewall's chains are refused. Tested over the shapes two machines of the first mesh reported live. The module's own tool stays.
This commit is contained in:
@@ -1,11 +1,15 @@
|
||||
{
|
||||
"name": "@novox/module-firewall",
|
||||
"name": "@novox/module-nftables",
|
||||
"version": "0.1.0",
|
||||
"description": "firewall — applies the mesh-computed packet filter (ADR 0045). Its diagnostic tool lives here.
|
||||
"description": "nftables — loads the mesh's packet filter and holds the node-packet-filter seat: its verbs rules, reload and remove (novox/hq ADR 0045, ADR 0169).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc client.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.0"
|
||||
"@novox/mesh-sdk": "^0.1.1"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/node": "^22.0.0",
|
||||
|
||||
Reference in New Issue
Block a user