The packet filter's tools are a bundle the node's runtime serves; its container goes (hq to-be 38 WP4) #239

Merged
mesh-admin merged 1 commits from feat/wp4-the-packet-filter-moves into main 2026-10-03 11:14:34 +00:00
Contributor

hq design 38 WP4 — the first holder moves. The live proof of ADR 0175.

What changes in modules/nftables:

  • module.json: the runtime container resource goes (with NET_ADMIN, the container-runtime capability and both build.on base images), and so do own-secrets and the mesh-state directory — only the container read that credential; the runtime speaks with the node's (zsh on #224 declares neither). The iptables package the image used to carry is declared on the host (all four nodes are Arch and already own /usr/bin/iptables through the iptables package, so this is a no-op there). The tools are declared as build.artifacts: [{tools, bundle, typescript, entrypoints: [tools/index.js]}]. Claims, filtering, package, units and service stay.
  • Dockerfile removed.
  • client.ts: the filter's commands run as given by root and through sudo -n otherwise — the runtime runs as the operator's account (to-be 38 WP4; root is the module's concern, ADR 0175 §4); listing needs root too. Sudo's absence, a missing command and a refusal are each named by how they failed (spawn error, sudo's own stderr line), not by matching prose. The filter file is the path filtering names, said once as a constant and held to the manifest by a test; no process-env lookup, since a bundle has no environment of its own and the runtime's env is shared by every bundle. A found firewall (ufw) that is absent guards nothing; one that is present but will not answer stops a removal rather than passing for inactive. A legacy tool that is present but fails is reported in rules, not swallowed.
  • tools/index.ts: FirewallClient.onThisMachine().
  • test/remove.test.ts: 9/9 — escalation, the filter-file/manifest tie, installed, the found-firewall cases. Compiled as the builder does (tsc, --rootDir ., against the SDK): clean, emits tools/index.js and client.js. Controller catalogue tests pass against this tree.

Reviewed with /code-review (high); every finding applied except one, recorded in design 38 instead: that the operator's account may escalate without a prompt is a machine fact the mesh neither declares nor checks (verified on all four nodes today).

Merge order: after mesh-tools #32 (hq issue 209) has merged and rolled to all four nodes. Without it, node-tools would load this bundle and serve nothing from it.

Proof after the push: node-packet-filter.rules@<node>, reload, remove answer from node-tools on all four; docker ps shows no mesh-nftables; status well.

hq design 38 WP4 — the first holder moves. The live proof of ADR 0175. What changes in `modules/nftables`: - `module.json`: the `runtime` container resource goes (with `NET_ADMIN`, the `container-runtime` capability and both `build.on` base images), and so do `own-secrets` and the `mesh-state` directory — only the container read that credential; the runtime speaks with the node's (zsh on #224 declares neither). The `iptables` package the image used to carry is declared on the host (all four nodes are Arch and already own `/usr/bin/iptables` through the `iptables` package, so this is a no-op there). The tools are declared as `build.artifacts: [{tools, bundle, typescript, entrypoints: [tools/index.js]}]`. Claims, filtering, package, units and service stay. - `Dockerfile` removed. - `client.ts`: the filter's commands run as given by root and through `sudo -n` otherwise — the runtime runs as the operator's account (to-be 38 WP4; root is the module's concern, ADR 0175 §4); listing needs root too. Sudo's absence, a missing command and a refusal are each named by how they failed (spawn error, sudo's own stderr line), not by matching prose. The filter file is the path `filtering` names, said once as a constant and held to the manifest by a test; no process-env lookup, since a bundle has no environment of its own and the runtime's env is shared by every bundle. A found firewall (ufw) that is absent guards nothing; one that is present but will not answer stops a removal rather than passing for inactive. A legacy tool that is present but fails is reported in `rules`, not swallowed. - `tools/index.ts`: `FirewallClient.onThisMachine()`. - `test/remove.test.ts`: 9/9 — escalation, the filter-file/manifest tie, `installed`, the found-firewall cases. Compiled as the builder does (tsc, `--rootDir .`, against the SDK): clean, emits `tools/index.js` and `client.js`. Controller catalogue tests pass against this tree. Reviewed with /code-review (high); every finding applied except one, recorded in design 38 instead: that the operator's account may escalate without a prompt is a machine fact the mesh neither declares nor checks (verified on all four nodes today). **Merge order:** after mesh-tools #32 (hq issue 209) has merged and rolled to all four nodes. Without it, node-tools would load this bundle and serve nothing from it. Proof after the push: `node-packet-filter.rules@<node>`, `reload`, `remove` answer from node-tools on all four; `docker ps` shows no `mesh-nftables`; `status` well.
jschoubben added 1 commit 2026-10-03 10:59:09 +00:00
nftables drops its container, NET_ADMIN, the container-runtime capability, the runtime base
images, the Dockerfile, and the bus credential and state directory only the container read;
its tools are declared as a TypeScript bundle the toolchain compiles and node-tools loads on
every node, and the iptables package the image used to carry is declared on the host. The
runtime runs as the operator's account, so the tool runs the filter's commands through sudo
without a prompt when it is not root (ADR 0175 §4, to-be 38 WP4), naming sudo's absence or
refusal by how it failed; the filter file is the path the manifest's filtering names, held to
it by a test; a found firewall that is present but will not answer stops a removal rather
than passing for inactive; a legacy tool that is present but fails is said, not swallowed.
jschoubben force-pushed feat/wp4-the-packet-filter-moves from 5d01258b67 to db5e7c80cf 2026-10-03 10:59:09 +00:00 Compare
mesh-admin merged commit 510de183b1 into main 2026-10-03 11:14:34 +00:00
mesh-admin deleted branch feat/wp4-the-packet-filter-moves 2026-10-03 11:14:34 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#239