The mesh answers only its own names privately; a public name resolves publicly (hq ADR 0191)

Every routed public name was published into each machine's hosts region at its serving node's
private address. ace's resolver also answers its LAN, so a phone there got the control-node's
tunnel address for the mail server and could not connect. Routes have internal names under the
serving node (ADR 0151), so only names under the mesh suffix are published now.
This commit is contained in:
2026-10-03 15:14:01 +02:00
parent eae0577567
commit 408f6dbad9
2 changed files with 50 additions and 5 deletions
@@ -0,0 +1,27 @@
package main
import (
"reflect"
"testing"
)
// The mesh's resolver holds only the mesh's own names (novox/hq ADR 0191): a routed public name is
// never given a private answer, and a route's internal name is.
func TestOnlyTheMeshsOwnNamesAreAnsweredPrivately(t *testing.T) {
routes := map[string]string{
"git.example.tld": "10.77.0.1",
"example.tld": "10.77.0.1",
"media.home.example": "10.77.0.2",
"git.anchor.internal": "10.77.0.1",
"media.homeserver.internal": "10.77.0.2",
"internal.example.tld": "10.77.0.1", // the suffix as a label, not as the zone
}
got := meshOwnNames(routes, "internal")
want := map[string]string{
"git.anchor.internal": "10.77.0.1",
"media.homeserver.internal": "10.77.0.2",
}
if !reflect.DeepEqual(got, want) {
t.Fatalf("names answered privately: %v\nwant only the mesh's own: %v", got, want)
}
}
+23 -5
View File
@@ -645,10 +645,9 @@ func renderingFor(ctx context.Context, open *stores, node string,
} }
} }
// And every routed name → the node that serves it (novox/hq ADR 0066). Alongside the // And every routed name under the mesh's own suffix → the node that serves it, alongside the
// `<node>.internal` names above, so a container — or an internal ACME validator — resolves a // `<node>.internal` names above (novox/hq ADR 0066, narrowed by ADR 0191). A public name is not
// routed name to the proxy that serves it, mesh-wide. The mesh publishes the names it was told // among them: the mesh gives no private answer for a name public DNS answers.
// to serve and knows nothing about what they mean.
// Kept apart from the machines, because a fact about the machines must not be handed the names // Kept apart from the machines, because a fact about the machines must not be handed the names
// the mesh merely serves (novox/hq 04-ISSUES/111). // the mesh merely serves (novox/hq 04-ISSUES/111).
machines := make(map[string]string, len(names)) machines := make(map[string]string, len(names))
@@ -659,7 +658,7 @@ func renderingFor(ctx context.Context, open *stores, node string,
if err != nil { if err != nil {
return catalogue.Rendering{}, inventory.Node{}, err return catalogue.Rendering{}, inventory.Node{}, err
} }
for name, at := range routes { for name, at := range meshOwnNames(routes, overlay.Suffix()) {
names[name] = at names[name] = at
} }
@@ -740,6 +739,25 @@ func renderingFor(ctx context.Context, open *stores, node string,
}, record, nil }, record, nil
} }
// meshOwnNames is the routed names the mesh may answer privately: those under its own suffix.
//
// **The mesh's resolver holds only the mesh's own names** (novox/hq ADR 0191). A routed public name
// was once published here at its serving node's private address, so an internal authority could
// reach it to certify it (ADR 0066). Every machine's resolver then answered public names with
// addresses only members can reach — and a resolver that also serves a LAN handed them to a phone
// on it, which could not reach the mail server while every check, run from a member, passed. A
// route is reached and certified inside the mesh by its internal name (ADR 0151); its public name
// resolves publicly, for members and everyone else alike.
func meshOwnNames(routes map[string]string, suffix string) map[string]string {
out := map[string]string{}
for name, at := range routes {
if strings.HasSuffix(name, "."+suffix) {
out[name] = at
}
}
return out
}
// routeNamesInTheMesh is every routed name and the address of the node that serves it (novox/hq // routeNamesInTheMesh is every routed name and the address of the node that serves it (novox/hq
// ADR 0066). // ADR 0066).
// //