Compare commits
5
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2b20a12c4a | ||
|
|
9c83dacfce | ||
|
|
64ba053f3b | ||
|
|
96416bd8a7 | ||
|
|
aaad02fd38 |
@@ -1102,6 +1102,7 @@ func (r Resolution) contributions(settings SettingsBy, grants []Grant,
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing to %s: %w", m.Module, to, err)
|
||||
}
|
||||
portOfEndpoint(values, endpointPorts(m))
|
||||
composeName(values, r.PublicDomain, r.At, reaches, endpointPorts(m), blocks)
|
||||
out[to] = append(out[to], Contribution{From: m.Module, Values: values})
|
||||
}
|
||||
@@ -1124,6 +1125,7 @@ func (r Resolution) contributions(settings SettingsBy, grants []Grant,
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing %s to %s: %w", m.Module, local, to, err)
|
||||
}
|
||||
portOfEndpoint(values, endpointPorts(m))
|
||||
composeName(values, r.PublicDomain, r.At, reaches, endpointPorts(m), blocks)
|
||||
out[to] = append(out[to], Contribution{From: m.Module, Values: values})
|
||||
}
|
||||
@@ -1837,3 +1839,32 @@ func endpointPorts(m Manifest) map[string]int {
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// portOfEndpoint fills in the port of the endpoint a contribution names, in place.
|
||||
//
|
||||
// **A contribution that names an endpoint must still carry that endpoint's port**, because everything
|
||||
// downstream reads the port: the provider is told where to reach the consumer, and the machine-side
|
||||
// redirection that turns a declared port into the number the machine published is keyed on it
|
||||
// (atMachinePort). A route that named only its endpoint left the proxy with no port at all, and a
|
||||
// proxy with no port has nothing to dial.
|
||||
//
|
||||
// Found before it shipped and after the catalogue had already been changed to name endpoints — the
|
||||
// manifests were merged and the mesh had not yet picked them up, so nothing was broken yet. The
|
||||
// declared port, not the machine one: the redirection happens later and is keyed on the declared
|
||||
// number, so filling in the machine port here would be redirected a second time or not at all.
|
||||
func portOfEndpoint(values map[string]any, ports map[string]int) {
|
||||
if values == nil {
|
||||
return
|
||||
}
|
||||
if _, already := values["port"]; already {
|
||||
// A route that says both is its own answer; the older shape repeated the port and is still read.
|
||||
return
|
||||
}
|
||||
name, ok := values[RouteEndpoint].(string)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
if port, found := ports[strings.TrimSpace(name)]; found {
|
||||
values["port"] = port
|
||||
}
|
||||
}
|
||||
|
||||
@@ -145,3 +145,61 @@ func TestAnUnnamedEndpointIsStillValid(t *testing.T) {
|
||||
t.Fatalf("a module with no route was refused: %v", got)
|
||||
}
|
||||
}
|
||||
|
||||
// **A route that names an endpoint still carries that endpoint's port.**
|
||||
//
|
||||
// Everything downstream reads the port: the provider is told where to reach the consumer, and the
|
||||
// redirection that turns a declared port into the number the machine published is keyed on it. A route
|
||||
// naming only its endpoint left the proxy with no port, and a proxy with no port has nothing to dial.
|
||||
//
|
||||
// Caught after the catalogue had already been changed to name endpoints, and before the mesh picked
|
||||
// those manifests up — which is the only reason nothing broke.
|
||||
func TestARouteNamingAnEndpointStillCarriesItsPort(t *testing.T) {
|
||||
m := aMediaServer()
|
||||
r := Resolution{Node: "anchor", Modules: []Manifest{m},
|
||||
PublicDomain: "example.test", At: "anchor.internal"}
|
||||
given, err := r.contributions(nil, nil, nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
var saw bool
|
||||
for _, c := range given["route"] {
|
||||
saw = true
|
||||
port, ok := asPort(c.Values["port"])
|
||||
if !ok {
|
||||
t.Fatalf("the route carries no port, so the proxy has nothing to dial: %v", c.Values)
|
||||
}
|
||||
if port != 80 {
|
||||
t.Fatalf("the route carries port %d, want the web endpoint's 80", port)
|
||||
}
|
||||
}
|
||||
if !saw {
|
||||
t.Fatal("the module contributed no route")
|
||||
}
|
||||
}
|
||||
|
||||
// And the declared port, not the machine one: the redirection to where the machine published it
|
||||
// happens later and is keyed on the declared number, so filling the machine port in here would be
|
||||
// redirected twice or not at all.
|
||||
func TestTheEndpointsDeclaredPortIsFilledInNotTheMachineOne(t *testing.T) {
|
||||
m := aMediaServer()
|
||||
values := map[string]any{RouteEndpoint: "web", "label": "media"}
|
||||
portOfEndpoint(values, endpointPorts(m))
|
||||
if got, _ := asPort(values["port"]); got != 80 {
|
||||
t.Fatalf("filled in port %d, want the declared 80", got)
|
||||
}
|
||||
// Then the ordinary redirection puts it where the machine published it.
|
||||
moved := atMachinePort(values, m.Module, map[string]map[int]int{"media": {80: 20009}})
|
||||
if got, _ := asPort(moved["port"]); got != 20009 {
|
||||
t.Fatalf("after redirection the port is %d, want the machine's 20009", got)
|
||||
}
|
||||
}
|
||||
|
||||
// A route that repeats a port keeps it, because that is the older shape and still read.
|
||||
func TestARouteThatRepeatsItsPortKeepsIt(t *testing.T) {
|
||||
values := map[string]any{RouteEndpoint: "web", "port": 8080}
|
||||
portOfEndpoint(values, map[string]int{"web": 80})
|
||||
if got, _ := asPort(values["port"]); got != 8080 {
|
||||
t.Fatalf("the port it stated was overwritten with %d", got)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -374,6 +374,25 @@ func AsNftables(rules []Rule, mesh []string, outward bool, foundation []int,
|
||||
b.WriteString(fmt.Sprintf("\t\tip6 saddr { %s } %s dport %d accept\n",
|
||||
strings.Join(six, ", "), rule.Protocol, rule.Port))
|
||||
}
|
||||
// **And this machine's own guests, which are part of what it hosts** (novox/hq ADR 0100:
|
||||
// the store is reachable "from a container on the node itself").
|
||||
//
|
||||
// The addresses above are the machines' own on the private network. A container reaching a
|
||||
// port on the machine it runs on comes from a bridge, so it matches none of them — and with
|
||||
// the runtime routing directly, that packet is delivered to this machine rather than
|
||||
// forwarded, so the forward chain's allowance never sees it either.
|
||||
//
|
||||
// Measured, and it was an outage: after a machine was converged, every module that reached
|
||||
// another by the machine's own name timed out. A web application logged
|
||||
// "connection to server at novox.internal (10.10.0.1), port 6852 failed: timeout expired"
|
||||
// for eleven hours while the mesh reported the machine healthy.
|
||||
//
|
||||
// Asked for by the link it arrives on, for the reason §4 no longer names an address: a
|
||||
// range describes one machine and goes stale in silence.
|
||||
if inward != "" {
|
||||
b.WriteString(fmt.Sprintf("\t\tiifname != { %s } %s dport %d accept\n",
|
||||
inward, rule.Protocol, rule.Port))
|
||||
}
|
||||
case FromEverywhere:
|
||||
b.WriteString(fmt.Sprintf("\t\t%s dport %d accept\n", rule.Protocol, rule.Port))
|
||||
}
|
||||
|
||||
@@ -804,3 +804,39 @@ func TestSSHIsNeverLeftWithoutARule(t *testing.T) {
|
||||
t.Fatalf("a machine with no mesh addresses has no ssh rule, so adopting it locks it:\n%s", nft)
|
||||
}
|
||||
}
|
||||
|
||||
// **This machine's own guests are part of what it hosts** (novox/hq ADR 0100: the store is reachable
|
||||
// "from a container on the node itself").
|
||||
//
|
||||
// The addresses a mesh-scoped rule admits are the machines' own on the private network. A container
|
||||
// reaching a port on the machine it runs on comes from a bridge, matching none of them — and where the
|
||||
// runtime routes directly, that packet is delivered to this machine rather than forwarded, so the
|
||||
// forward chain's allowance never sees it either.
|
||||
//
|
||||
// Measured, and it was an outage: after a machine was converged, every module reaching another by the
|
||||
// machine's own name timed out for eleven hours while the mesh reported the machine healthy.
|
||||
func TestAMeshScopedPortAdmitsThisMachinesOwnGuests(t *testing.T) {
|
||||
nft := AsNftables(mustFilter(t, Resolution{Modules: []Manifest{
|
||||
{Module: "store", Listens: []Listening{{Port: 5432, From: FromMesh}}},
|
||||
}}, nil), []string{"10.10.0.1", "10.10.0.2"}, false, nil, []string{"eth0"}, "mesh0")
|
||||
|
||||
// The private network's own addresses, as before.
|
||||
if !strings.Contains(nft, "ip saddr { 10.10.0.1, 10.10.0.2 } tcp dport 5432 accept") {
|
||||
t.Fatalf("the private network no longer reaches a mesh-scoped port:\n%s", nft)
|
||||
}
|
||||
// And this machine's guests, by the link they arrive on.
|
||||
if !strings.Contains(nft, `iifname != { "eth0", "mesh0" } tcp dport 5432 accept`) {
|
||||
t.Fatalf("a container on this machine cannot reach a mesh-scoped port on it, which is the "+
|
||||
"outage this test exists for:\n%s", nft)
|
||||
}
|
||||
}
|
||||
|
||||
// A port open to everything needs no such line — it is already open to a guest.
|
||||
func TestAPublicPortNeedsNoGuestLine(t *testing.T) {
|
||||
nft := AsNftables(mustFilter(t, Resolution{Modules: []Manifest{
|
||||
{Module: "web", Listens: []Listening{{Port: 443, From: FromEverywhere}}},
|
||||
}}, nil), []string{"10.10.0.1"}, false, nil, []string{"eth0"}, "mesh0")
|
||||
if strings.Count(nft, `iifname != { "eth0", "mesh0" } tcp dport 443`) != 0 {
|
||||
t.Fatalf("a public port was given a guest line it does not need:\n%s", nft)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user