Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict that depended on what sat beside the checkout: a stale or dirty sibling failed them on a desktop, and a missing one skipped them unseen. They now read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is absent there, and elsewhere a copy captured at a named commit. The skip had hidden that the builder test read a module retired by ADR 0190. The systemd reading test no longer counts the machine's own environment.d.
87 lines
2.2 KiB
Plaintext
87 lines
2.2 KiB
Plaintext
{
|
|
"module": "nftables",
|
|
"version": "1",
|
|
"upgrade": {
|
|
"policy": "record",
|
|
"why": "the machine's packet filter: a build that breaks it can cut the machine off from the bus, and then neither the gate's rollback nor a push reaches it (hq ADR 0236)"
|
|
},
|
|
"capabilities": [
|
|
"firewall"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-packet-filter",
|
|
"scope": "node",
|
|
"serves": [
|
|
"rules",
|
|
"reload",
|
|
"remove"
|
|
]
|
|
}
|
|
],
|
|
"filtering": {
|
|
"into": "/etc/nftables.conf"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "nftables"
|
|
},
|
|
{
|
|
"id": "legacy-tools",
|
|
"type": "package",
|
|
"package": "iptables"
|
|
},
|
|
{
|
|
"id": "unit",
|
|
"type": "file",
|
|
"path": "/etc/systemd/system/mesh-filter.service",
|
|
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
|
|
"mode": "0644"
|
|
},
|
|
{
|
|
"id": "stock-unit-stop",
|
|
"type": "file",
|
|
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
|
|
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
|
|
"mode": "0644"
|
|
},
|
|
{
|
|
"id": "load",
|
|
"type": "service",
|
|
"unit": "mesh-filter.service",
|
|
"state": "running",
|
|
"boot": "enabled",
|
|
"restart-on": [
|
|
"unit",
|
|
"stock-unit-stop"
|
|
],
|
|
"reload-on": [
|
|
"filtering"
|
|
]
|
|
},
|
|
{
|
|
"id": "front-end",
|
|
"type": "package",
|
|
"package": "ufw",
|
|
"absent": true
|
|
}
|
|
],
|
|
"tools": [
|
|
"firewall_rules"
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"tools/index.js"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|