From ba0f44a36dde0bd7ca20219f33aa14e72070164f Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 18:01:04 +0200 Subject: [PATCH] Say in the converge preview that routed traffic is not previewed and is dropped unless declared (hq ADR 0100) --- cmd/mesh-controller/adopting_test.go | 3 +++ cmd/mesh-controller/adoption.go | 5 +++++ 2 files changed, 8 insertions(+) diff --git a/cmd/mesh-controller/adopting_test.go b/cmd/mesh-controller/adopting_test.go index e52a6f4..bc39707 100644 --- a/cmd/mesh-controller/adopting_test.go +++ b/cmd/mesh-controller/adopting_test.go @@ -171,6 +171,9 @@ func TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken(t *testing.T) "notes\n replacing the found file /etc/notes.conf (original kept at", "assigns nftables", "the found firewall (ufw) is disabled, never flushed", + // What it routes is not a listener: said not to be previewed, and to be dropped. + "not previewed: traffic the machine routes that is not a published port", + "the derived filter drops it unless a module declares it", } { if !strings.Contains(preview, want) { t.Errorf("the preview does not say %q:\n%s", want, preview) diff --git a/cmd/mesh-controller/adoption.go b/cmd/mesh-controller/adoption.go index 152998c..b63616b 100644 --- a/cmd/mesh-controller/adoption.go +++ b/cmd/mesh-controller/adoption.go @@ -276,6 +276,11 @@ func previewOf(node string, reported inventory.Adoption, derived derivedFilter, if len(reported.Reachable) == 0 { b.WriteString(" nothing reported\n") } + // What the machine routes for others is not a listener and not a published port, so nothing + // above can show it; the derived filter's forward chain drops it all the same. + b.WriteString(" not previewed: traffic the machine routes that is not a published port " + + "(a tunnel, NAT in the found firewall) — the derived filter drops it unless a module " + + "declares it\n") isTaken := map[string]bool{} for _, m := range taken {