The filter constrains what arrives from outside, and names no network #135

Merged
mesh-admin merged 1 commits from feat/filter-what-arrives-from-outside into main 2026-09-28 23:01:53 +00:00
Contributor

novox/hq ADR 0140, superseding 0137 and 0139. What a converged machine loads today:

chain forward {
    policy drop;
    ct state established,related accept
    ip saddr 172.16.0.0/12 accept      <- constants in this repository
    ip saddr 192.168.128.0/17 accept
    ip saddr 10.0.0.0/8 accept         <- and what 0137 made recordable
    ip saddr 192.168.16.0/20 accept
    ... four more

It blocks everything passing through the machine and then allows the machine's own containers back by
naming the address ranges they sit on. Every way of keeping that list correct fails: a constant
describes one machine; a recorded range goes stale in silence and cannot tell a network the mesh made
from one a predecessor left behind; generating it from the modules would put half the rule set on the
machine. The list should not exist, because the mesh has no position on a container reaching outward —
that is not a port opened to anybody.

So both chains are written around the links traffic arrives on. What did not arrive from outside is
accepted in one line; what did arrive meets the declared rules. The tunnel is named beside the outward
links rather than treated as inside, or a port nothing declares would become reachable from every
machine in the mesh. A machine's own guests keep asking it for an address and for names, admitted by
the link they arrive on rather than by a range.

A machine that has reported no outward link is sent no filter at all and keeps the one it has, refused
in the control plane where a person reads it rather than as a rule set that will not load.

Removes the two constants, node networks — answered with a sentence saying where it went, because it
was the documented way to stop a flip cutting a machine off and somebody will reasonably still type it
— and migration 0044 drops the column. What 0043 recorded is not migrated: those ranges answered a
question that no longer exists, and the traffic they allowed is now allowed by not having arrived from
outside.

Ports keep following the modules exactly as before. Assign a module and the port its assignment says
it reaches on opens; no network is named anywhere by anybody.

Tests: seven on the new shape, and the two that matter fail against the old behaviour naming the exact
ranges — proved by reverting once. All four machines are already running a host that reports its links.

novox/hq ADR 0140, superseding 0137 and 0139. What a converged machine loads today: ``` chain forward { policy drop; ct state established,related accept ip saddr 172.16.0.0/12 accept <- constants in this repository ip saddr 192.168.128.0/17 accept ip saddr 10.0.0.0/8 accept <- and what 0137 made recordable ip saddr 192.168.16.0/20 accept ... four more ``` It blocks everything passing through the machine and then allows the machine's own containers back by naming the address ranges they sit on. Every way of keeping that list correct fails: a constant describes one machine; a recorded range goes stale in silence and cannot tell a network the mesh made from one a predecessor left behind; generating it from the modules would put half the rule set on the machine. The list should not exist, because the mesh has no position on a container reaching outward — that is not a port opened to anybody. So both chains are written around the links traffic arrives on. What did not arrive from outside is accepted in one line; what did arrive meets the declared rules. The tunnel is named beside the outward links rather than treated as inside, or a port nothing declares would become reachable from every machine in the mesh. A machine's own guests keep asking it for an address and for names, admitted by the link they arrive on rather than by a range. A machine that has reported no outward link is sent no filter at all and keeps the one it has, refused in the control plane where a person reads it rather than as a rule set that will not load. Removes the two constants, `node networks` — answered with a sentence saying where it went, because it was the documented way to stop a flip cutting a machine off and somebody will reasonably still type it — and migration 0044 drops the column. What 0043 recorded is not migrated: those ranges answered a question that no longer exists, and the traffic they allowed is now allowed by not having arrived from outside. Ports keep following the modules exactly as before. Assign a module and the port its assignment says it reaches on opens; no network is named anywhere by anybody. Tests: seven on the new shape, and the two that matter fail against the old behaviour naming the exact ranges — proved by reverting once. All four machines are already running a host that reports its links.
mesh-admin added 1 commit 2026-09-28 23:01:52 +00:00
The forward chain blocked everything passing through the machine and then allowed
the machine's own containers back by naming their address ranges: 172.16.0.0/12 and
192.168.128.0/17 fixed here, the rest recorded per machine by 0043. Every way of
keeping that list correct fails — a constant describes one machine, a recorded range
goes stale in silence and cannot tell a network the mesh made from one a predecessor
left behind, and generating it from the modules would put half the rule set on the
machine.

The mesh has no position on a container reaching outward: that is not a port opened
to anybody. So both chains are written around the links traffic arrives on. What did
not arrive from outside is accepted in one line; what did meets the declared rules.
The tunnel is named beside the outward links rather than treated as inside, or a port
nothing declares would be reachable from every machine in the mesh.

A machine that has not reported an outward link is sent no filter and keeps the one
it has, refused where a person reads it rather than as a rule set that will not load.

Removes the two constants, `node networks`, and the column behind it. novox/hq ADR
0140, superseding 0137 and 0139.
jschoubben force-pushed feat/filter-what-arrives-from-outside from ab74988f1c to fe5988c536 2026-09-28 23:01:53 +00:00 Compare
mesh-admin merged commit 76ac3c99bd into main 2026-09-28 23:01:53 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#135