Enrolling ace applied adoption.opening-tcp-5671-incoming to it — a from-anywhere (v4+v6) opening for 5671 where nothing on ace listens (the ace session caught it). The foundation opening exists to widen the broker's from: mesh listen to from-anywhere, because a machine enrolling isn't on the mesh yet and its first dial would be refused mesh-only — but that belongs on the broker's host alone; a node that only dials out needs no incoming rule. foundationPortsFor keeps the port only when a module resolved onto this node listens on it. Two tests (broker host keeps it; a dial-only node gets nothing); full suite green.
Enrolling ace applied `adoption.opening-tcp-5671-incoming` to it — a from-anywhere (v4+v6) opening for 5671 where nothing on ace listens (the ace session caught it). The foundation opening exists to *widen* the broker's `from: mesh` listen to from-anywhere, because a machine enrolling isn't on the mesh yet and its first dial would be refused mesh-only — but that belongs on the broker's host alone; a node that only dials out needs no incoming rule. `foundationPortsFor` keeps the port only when a module resolved onto this node listens on it. Two tests (broker host keeps it; a dial-only node gets nothing); full suite green.
Enrolling ace applied adoption.opening-tcp-5671-incoming to it, opening
5671 from anywhere (v4+v6) where nothing listens — the ace session
caught it. foundation ports widen the broker's from:mesh port to
from-anywhere so a machine that is not yet on the mesh can make its
first dial; that belongs on the broker's host alone. foundationPortsFor
keeps the port only when a module resolved onto this node listens on
it, so novox opens 5671 and a node that merely dials out opens nothing.
Two tests, both directions.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Enrolling ace applied
adoption.opening-tcp-5671-incomingto it — a from-anywhere (v4+v6) opening for 5671 where nothing on ace listens (the ace session caught it). The foundation opening exists to widen the broker'sfrom: meshlisten to from-anywhere, because a machine enrolling isn't on the mesh yet and its first dial would be refused mesh-only — but that belongs on the broker's host alone; a node that only dials out needs no incoming rule.foundationPortsForkeeps the port only when a module resolved onto this node listens on it. Two tests (broker host keeps it; a dial-only node gets nothing); full suite green.