The roster publishes a route's internal name, never its public one (hq ADR 0191)
NamesServed read a route's public `name` and plan.go then filtered by suffix — telling the mesh's names from public ones by their spelling, when the mesh composed both itself. It now publishes the `internal-name` it composed under the serving node (ADR 0151); the suffix filter is gone.
This commit is contained in:
@@ -645,9 +645,9 @@ func renderingFor(ctx context.Context, open *stores, node string,
|
||||
}
|
||||
}
|
||||
|
||||
// And every routed name under the mesh's own suffix → the node that serves it, alongside the
|
||||
// `<node>.internal` names above (novox/hq ADR 0066, narrowed by ADR 0191). A public name is not
|
||||
// among them: the mesh gives no private answer for a name public DNS answers.
|
||||
// And every route's internal name → the node that serves it, alongside the `<node>.internal`
|
||||
// names above (novox/hq ADR 0066, narrowed by ADR 0191). A route's public name is not among
|
||||
// them: the mesh gives no private answer for a name public DNS answers.
|
||||
// Kept apart from the machines, because a fact about the machines must not be handed the names
|
||||
// the mesh merely serves (novox/hq 04-ISSUES/111).
|
||||
machines := make(map[string]string, len(names))
|
||||
@@ -658,7 +658,7 @@ func renderingFor(ctx context.Context, open *stores, node string,
|
||||
if err != nil {
|
||||
return catalogue.Rendering{}, inventory.Node{}, err
|
||||
}
|
||||
for name, at := range meshOwnNames(routes, overlay.Suffix()) {
|
||||
for name, at := range routes {
|
||||
names[name] = at
|
||||
}
|
||||
|
||||
@@ -739,25 +739,6 @@ func renderingFor(ctx context.Context, open *stores, node string,
|
||||
}, record, nil
|
||||
}
|
||||
|
||||
// meshOwnNames is the routed names the mesh may answer privately: those under its own suffix.
|
||||
//
|
||||
// **The mesh's resolver holds only the mesh's own names** (novox/hq ADR 0191). A routed public name
|
||||
// was once published here at its serving node's private address, so an internal authority could
|
||||
// reach it to certify it (ADR 0066). Every machine's resolver then answered public names with
|
||||
// addresses only members can reach — and a resolver that also serves a LAN handed them to a phone
|
||||
// on it, which could not reach the mail server while every check, run from a member, passed. A
|
||||
// route is reached and certified inside the mesh by its internal name (ADR 0151); its public name
|
||||
// resolves publicly, for members and everyone else alike.
|
||||
func meshOwnNames(routes map[string]string, suffix string) map[string]string {
|
||||
out := map[string]string{}
|
||||
for name, at := range routes {
|
||||
if strings.HasSuffix(name, "."+suffix) {
|
||||
out[name] = at
|
||||
}
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// routeNamesInTheMesh is every routed name and the address of the node that serves it (novox/hq
|
||||
// ADR 0066).
|
||||
//
|
||||
|
||||
Reference in New Issue
Block a user