A taken tunnel brings its ListenPort, even on a node the hub cannot dial #75

Merged
jschoubben merged 1 commits from fix/a-taken-tunnel-brings-its-port into main 2026-09-26 20:34:10 +00:00
Owner

The shanks session's report, fixed: ListenPort was gated on Reachable (Endpoint set), conflating "a LAN peer dials me here" with "the hub can dial me". A home node behind NAT that took over a tunnel got no ListenPort, so the takeover guard refused overlay-up — and the guard's suggested remedy (re-place with an endpoint) breaks the tunnel (stops keepalive, hands the hub a private LAN address). TakeOver now carries the found tunnel's port (already known to the controller via Tunnel.Port), and the interface listens on it when not otherwise reachable. Two tests; reachable nodes unchanged. Unblocks shanks and ace identically. MTU (the second gap) follows separately.

The shanks session's report, fixed: `ListenPort` was gated on `Reachable` (Endpoint set), conflating "a LAN peer dials me here" with "the hub can dial me". A home node behind NAT that took over a tunnel got no ListenPort, so the takeover guard refused `overlay-up` — and the guard's suggested remedy (re-place with an endpoint) breaks the tunnel (stops keepalive, hands the hub a private LAN address). `TakeOver` now carries the found tunnel's port (already known to the controller via `Tunnel.Port`), and the interface listens on it when not otherwise reachable. Two tests; reachable nodes unchanged. Unblocks shanks and ace identically. MTU (the second gap) follows separately.
jschoubben added 1 commit 2026-09-26 20:33:39 +00:00
A home node behind NAT (no Endpoint → not Reachable) that took over a
tunnel must still listen on that tunnel's port: its LAN peers dial it
there. ListenPort was gated on Reachable, which conflated 'a peer dials
me here' with 'the hub can dial me' — so the takeover guard refused
overlay-up, and the guard's suggested remedy (re-place with an
endpoint) breaks a NAT'd node's path: it stops keepalive and hands the
hub a private LAN address to dial. TakeOver now carries the found
tunnel's port (already known to the controller), and the interface
listens on it when the node is not otherwise reachable. Two tests;
Endpoint-reachable nodes keep the old path unchanged.
jschoubben merged commit 50878a9d98 into main 2026-09-26 20:34:10 +00:00
jschoubben deleted branch fix/a-taken-tunnel-brings-its-port 2026-09-26 20:34:10 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#75