nftables holds the node-packet-filter seat: rules, reload and remove, from a runtime with NET_ADMIN (hq ADR 0169) #216

Merged
mesh-admin merged 1 commits from feat/the-firewall-seat-serves-its-verbs into main 2026-10-02 11:33:47 +00:00
Contributor

The nftables module gains a runtime — the tool runtime with nftables and iptables in its image, on the machine's network with capabilities: ["NET_ADMIN"] — and claims the node-packet-filter seat's three verbs: rules, reload, remove. remove takes a rule set exactly as node show lists it (ADR 0168) and refuses the mesh's tables, the runtime's own chains, a built-in chain and an active found firewall's chains; a predecessor's chain loses the jumps into it and goes, the runtime's user chain is emptied back to its return. Tested over the shapes two machines reported live. The module's own firewall_rules tool stays, now registered under the module's name.

Merge after mesh-host 68 has rolled (the runtime declares a capability an older host refuses) and after mesh-controller 212 (the seat's verbs, which the claim is held to). The module's policy is record: push each machine after the build.

The nftables module gains a runtime — the tool runtime with nftables and iptables in its image, on the machine's network with `capabilities: ["NET_ADMIN"]` — and claims the `node-packet-filter` seat's three verbs: `rules`, `reload`, `remove`. `remove` takes a rule set exactly as `node show` lists it (ADR 0168) and refuses the mesh's tables, the runtime's own chains, a built-in chain and an active found firewall's chains; a predecessor's chain loses the jumps into it and goes, the runtime's user chain is emptied back to its return. Tested over the shapes two machines reported live. The module's own `firewall_rules` tool stays, now registered under the module's name. **Merge after mesh-host 68 has rolled** (the runtime declares a capability an older host refuses) and after mesh-controller 212 (the seat's verbs, which the claim is held to). The module's policy is record: push each machine after the build.
mesh-admin added 1 commit 2026-10-02 11:28:56 +00:00
The seat's three verbs over the machine's own tools: the filter as enforced
(nftables and the legacy filter), the mesh's own table reloaded from its file,
and one rule set the mesh did not write removed by the name the host reports
it under (ADR 0168) — a predecessor's chain loses its jumps and goes, the
runtime's user chain is emptied back to its return, a table of the machine's
own goes whole; the mesh's tables, the runtime's chains, a built-in chain and
an active found firewall's chains are refused. Tested over the shapes two
machines of the first mesh reported live. The module's own tool stays.
mesh-admin merged commit 1c201d59c9 into main 2026-10-02 11:33:47 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#216