Names, from the same graph as the network

Step 5 of the connectivity order. Every node's internal name resolves to its
overlay address, on every node, computed centrally because it needs every node
at once.

Under `.internal`, which IANA reserved for exactly this in 2024 -- a name there
can never collide with a public one, so an internal name that leaks into a
public resolver fails rather than reaching a stranger's machine. The suffix is
settable for a mesh that wants its own.

Delivered in the same declaration as the peer list rather than a second one. A
node holding the peers and not the names, or the reverse, is half on the
network for as long as that lasts.

This is not the /etc/hosts floor the design removes. That floor existed because
a node had to reach the mesh's database before its own DNS worked -- a fallback
for a circularity that is now gone. This is the mechanism: the complete set of
names, generated whole and owned by the mesh, rather than a patch written
underneath something else. A resolver daemon becomes necessary when names are
wanted that are not one-per-node, and that is not yet true.

A node resolves its own name to its overlay address rather than a loopback,
because a service binding to the name it was given would otherwise listen
somewhere nothing else can reach -- and the failure would appear on every other
machine rather than that one.

A node with no address gets no name. A name resolving to nothing is worse than
no name: connecting to an address that does not answer hangs, where a name that
does not resolve fails at once and says which name it was.

Found while writing it: a test asserting every file in the declaration is mode
0600 would have forced /etc/hosts to 0600 and broken every lookup on the
machine, to protect a file that is not secret.

Verified in the lab: three machines, nine name lookups, each resolving to the
right overlay address and reaching it.
This commit is contained in:
2026-08-29 19:58:01 +02:00
parent 8b974deb42
commit fc1417be72
5 changed files with 229 additions and 5 deletions
+9 -3
View File
@@ -9,7 +9,7 @@ import (
func declarationFor(t *testing.T, node Node, peers []Peer) (string, []map[string]any) {
t.Helper()
raw, err := Declaration(node, peers, "")
raw, err := Declaration(node, peers, nil, "")
if err != nil {
t.Fatal(err)
}
@@ -85,11 +85,17 @@ func TestTheInterfaceComesBackAfterAReboot(t *testing.T) {
func TestTheConfigurationIsNotWorldReadable(t *testing.T) {
// It lists every peer's key and endpoint, which is a map of the mesh. Not secret the way a
// private key is, and not something to leave readable on a machine somebody else also uses.
// The peer list specifically, not every file. `/etc/hosts` is in here too and must be
// world-readable, or nothing on the machine resolves anything — a check that swept all files
// would force it to 0600 and break the machine to protect a file that is not secret.
_, resources := declarationFor(t, Node{Name: "laptop", Key: "PUB", Address: "10.42.0.2"}, nil)
for _, r := range resources {
if r["type"] == "file" && r["mode"] != "0600" {
if r["id"] == "overlay-config" && r["mode"] != "0600" {
t.Errorf("the peer list is mode %v", r["mode"])
}
if r["id"] == "mesh-names" && r["mode"] != "0644" {
t.Errorf("the name file is mode %v; nothing on the machine could read it", r["mode"])
}
}
}
@@ -121,7 +127,7 @@ func TestTheFileSaysNotToEditIt(t *testing.T) {
func TestANodeWithNoAddressIsRefused(t *testing.T) {
// Rather than a configuration with a blank address, which wg-quick would reject on the
// machine, at boot, where the failure is much harder to see.
if _, err := Declaration(Node{Name: "laptop", Key: "PUB"}, nil, ""); err == nil {
if _, err := Declaration(Node{Name: "laptop", Key: "PUB"}, nil, nil, ""); err == nil {
t.Fatal("a node with no overlay address was given a configuration")
}
}