Do not guard a port this node is told to open to everyone (hq ADR 0103)

This commit is contained in:
2026-09-22 19:44:35 +02:00
parent dd6aad4a2f
commit 0f3eedd163
2 changed files with 34 additions and 2 deletions
+15 -2
View File
@@ -610,13 +610,21 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
func (r Resolution) guarded(out []map[string]any, owner map[string]string, rules []Rule,
with Rendering) []int {
meshOnly := map[int]bool{}
fromEverywhere := map[int]bool{}
for _, rule := range rules {
if rule.Protocol == "tcp" && rule.From == FromMesh {
if rule.Protocol != "tcp" {
continue
}
switch rule.From {
case FromMesh:
meshOnly[rule.Port] = true
case FromEverywhere:
fromEverywhere[rule.Port] = true
}
}
for _, port := range with.Foundation {
delete(meshOnly, port)
fromEverywhere[port] = true
}
seen := map[int]bool{}
var ports []int
@@ -655,7 +663,12 @@ func (r Resolution) guarded(out []map[string]any, owner map[string]string, rules
}
}
}
guard(at)
// Not what this node is told to open to everyone: a per-node exposure setting that
// widens a guarded port is the operator saying so, and declaring an opening for it
// and a guard dropping it would be one statement refusing the other.
if !fromEverywhere[at] {
guard(at)
}
}
}
sort.Ints(ports)