The nftables module gains a runtime — the tool runtime with nftables and iptables in its image, on the machine's network with capabilities: ["NET_ADMIN"] — and claims the node-packet-filter seat's three verbs: rules, reload, remove. remove takes a rule set exactly as node show lists it (ADR 0168) and refuses the mesh's tables, the runtime's own chains, a built-in chain and an active found firewall's chains; a predecessor's chain loses the jumps into it and goes, the runtime's user chain is emptied back to its return. Tested over the shapes two machines reported live. The module's own firewall_rules tool stays, now registered under the module's name.
Merge after mesh-host 68 has rolled (the runtime declares a capability an older host refuses) and after mesh-controller 212 (the seat's verbs, which the claim is held to). The module's policy is record: push each machine after the build.
The nftables module gains a runtime — the tool runtime with nftables and iptables in its image, on the machine's network with `capabilities: ["NET_ADMIN"]` — and claims the `node-packet-filter` seat's three verbs: `rules`, `reload`, `remove`. `remove` takes a rule set exactly as `node show` lists it (ADR 0168) and refuses the mesh's tables, the runtime's own chains, a built-in chain and an active found firewall's chains; a predecessor's chain loses the jumps into it and goes, the runtime's user chain is emptied back to its return. Tested over the shapes two machines reported live. The module's own `firewall_rules` tool stays, now registered under the module's name.
**Merge after mesh-host 68 has rolled** (the runtime declares a capability an older host refuses) and after mesh-controller 212 (the seat's verbs, which the claim is held to). The module's policy is record: push each machine after the build.
The seat's three verbs over the machine's own tools: the filter as enforced
(nftables and the legacy filter), the mesh's own table reloaded from its file,
and one rule set the mesh did not write removed by the name the host reports
it under (ADR 0168) — a predecessor's chain loses its jumps and goes, the
runtime's user chain is emptied back to its return, a table of the machine's
own goes whole; the mesh's tables, the runtime's chains, a built-in chain and
an active found firewall's chains are refused. Tested over the shapes two
machines of the first mesh reported live. The module's own tool stays.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The nftables module gains a runtime — the tool runtime with nftables and iptables in its image, on the machine's network with
capabilities: ["NET_ADMIN"]— and claims thenode-packet-filterseat's three verbs:rules,reload,remove.removetakes a rule set exactly asnode showlists it (ADR 0168) and refuses the mesh's tables, the runtime's own chains, a built-in chain and an active found firewall's chains; a predecessor's chain loses the jumps into it and goes, the runtime's user chain is emptied back to its return. Tested over the shapes two machines reported live. The module's ownfirewall_rulestool stays, now registered under the module's name.Merge after mesh-host 68 has rolled (the runtime declares a capability an older host refuses) and after mesh-controller 212 (the seat's verbs, which the claim is held to). The module's policy is record: push each machine after the build.