A taken tunnel brings its ListenPort, even on a node the hub cannot dial
A home node behind NAT (no Endpoint → not Reachable) that took over a tunnel must still listen on that tunnel's port: its LAN peers dial it there. ListenPort was gated on Reachable, which conflated 'a peer dials me here' with 'the hub can dial me' — so the takeover guard refused overlay-up, and the guard's suggested remedy (re-place with an endpoint) breaks a NAT'd node's path: it stops keepalive and hands the hub a private LAN address to dial. TakeOver now carries the found tunnel's port (already known to the controller), and the interface listens on it when the node is not otherwise reachable. Two tests; Endpoint-reachable nodes keep the old path unchanged.
This commit is contained in:
@@ -260,3 +260,29 @@ func TestTakingOverAFoundTunnelIsSaidOnTheInterfacesService(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestATakenTunnelBringsItsListenPortEvenWhenNotDialable(t *testing.T) {
|
||||
// A home node behind NAT (no Endpoint, so not Reachable) that took over a tunnel must still
|
||||
// listen on that tunnel's port, because its LAN peers dial it there (novox/hq: a taken tunnel
|
||||
// brings its port). Without this the takeover guard refuses overlay-up.
|
||||
config, _ := declarationFor(t, Node{
|
||||
Name: "shanks", Key: "SPOKE", Address: "10.10.0.3",
|
||||
TakesOver: &TakeOver{Interface: "wg0", Unit: "wg-quick@wg0", Port: 51820},
|
||||
}, nil)
|
||||
|
||||
if !strings.Contains(config, "ListenPort = 51820") {
|
||||
t.Fatalf("a taken tunnel's port must be the mesh interface's ListenPort:\n%s", config)
|
||||
}
|
||||
if strings.Contains(config, "Endpoint =") {
|
||||
t.Error("a node that only listens for LAN peers must not advertise an endpoint")
|
||||
}
|
||||
}
|
||||
|
||||
func TestANodeWithNoTunnelAndNoEndpointStillListensOnNothing(t *testing.T) {
|
||||
// The guard against over-emitting: a plain spoke with neither an endpoint nor a taken tunnel
|
||||
// writes no ListenPort — it purely dials out.
|
||||
config, _ := declarationFor(t, Node{Name: "laptop", Key: "K", Address: "10.10.0.9"}, nil)
|
||||
if strings.Contains(config, "ListenPort") {
|
||||
t.Fatalf("a dial-only node needs no ListenPort:\n%s", config)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user