The intrusion-prevention seat serves status, banned, ban and unban; the proxy logs a refused name (hq ADR 0179) #219

Merged
mesh-admin merged 1 commits from feat/the-intrusion-seat-serves-its-verbs into main 2026-10-02 15:15:42 +00:00
Contributor

The node-intrusion-prevention seat row gains four verbs every holder owes, as the packet filter's holds three (ADR 0170). The route proxy logs refused: no route for "<name>", asked from <addr> when a name this mesh does not serve is asked for, so the proxy's own jail (declared in mesh-catalog) can read it. Merge after mesh-host has rolled and before mesh-catalog, whose fail2ban module claims the verbs.

The `node-intrusion-prevention` seat row gains four verbs every holder owes, as the packet filter's holds three (ADR 0170). The route proxy logs `refused: no route for "<name>", asked from <addr>` when a name this mesh does not serve is asked for, so the proxy's own jail (declared in mesh-catalog) can read it. Merge after mesh-host has rolled and before mesh-catalog, whose fail2ban module claims the verbs.
mesh-admin added 1 commit 2026-10-02 15:03:20 +00:00
Every holder of node-intrusion-prevention owes the four verbs, as the packet filter's holder owes
its three (ADR 0170). The proxy says in its log when a name this mesh does not serve is asked for,
with the asking address last, so its own jail can read it.
mesh-admin merged commit e5e1666f91 into main 2026-10-02 15:15:42 +00:00
mesh-admin deleted branch feat/the-intrusion-seat-serves-its-verbs 2026-10-02 15:15:42 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#219