From 14b3ffbd409a6175762b870009e7128529925559 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 18:00:54 +0200 Subject: [PATCH] Guard only packets addressed to this machine, and load the guard before the network and stop it only at shutdown (hq ADR 0103) --- internal/bootstrap/adopted.go | 9 ++++--- internal/bootstrap/adopted_test.go | 38 +++++++++++++++++++++++++++++- 2 files changed, 43 insertions(+), 4 deletions(-) diff --git a/internal/bootstrap/adopted.go b/internal/bootstrap/adopted.go index 0e3dedd..c211059 100644 --- a/internal/bootstrap/adopted.go +++ b/internal/bootstrap/adopted.go @@ -36,7 +36,8 @@ const ( // by default; it refuses the ports except from the machine itself — its loopback and the container // runtime's own networks — and from the private network, known by the interface a packet arrives // on and never by its source address; at prerouting, ahead of the runtime's destination -// translation, in the inet family so both address families. +// translation, in the inet family so both address families. It matches only packets addressed to +// this machine: what the machine routes for others is never its business (novox/hq ADR 0103). // // Character for character the controller's (mesh-controller internal/catalogue AsGuard); a test // on each side holds its copy to the same golden text. @@ -53,7 +54,7 @@ func AsGuard(ports []int) string { b.WriteString("table inet mesh_guard {\n") b.WriteString("\tchain prerouting {\n") b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n") - fmt.Fprintf(&b, "\t\tiifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+ + fmt.Fprintf(&b, "\t\tfib daddr type local iifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+ "iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", ")) b.WriteString("\t}\n") b.WriteString("}\n") @@ -65,8 +66,10 @@ func AsGuard(ports []int) string { func guardUnitText() string { return "[Unit]\n" + "Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" + - "Before=network-pre.target\n" + + "DefaultDependencies=no\n" + "Wants=network-pre.target\n" + + "Before=network-pre.target shutdown.target\n" + + "Conflicts=shutdown.target\n" + "\n" + "[Service]\n" + "Type=oneshot\n" + diff --git a/internal/bootstrap/adopted_test.go b/internal/bootstrap/adopted_test.go index dd6e8e6..b9e441b 100644 --- a/internal/bootstrap/adopted_test.go +++ b/internal/bootstrap/adopted_test.go @@ -21,7 +21,7 @@ delete table inet mesh_guard table inet mesh_guard { chain prerouting { type filter hook prerouting priority raw; policy accept; - iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop + fib daddr type local iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop } } ` @@ -32,6 +32,42 @@ func TestTheGuardIsExactlyThisTable(t *testing.T) { } } +// The same golden unit the controller's test holds its guard unit to. It is loaded before the +// network is up, so it carries no default dependencies, and it is stopped only at shutdown. +const goldenGuardUnit = `[Unit] +Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100) +DefaultDependencies=no +Wants=network-pre.target +Before=network-pre.target shutdown.target +Conflicts=shutdown.target + +[Service] +Type=oneshot +RemainAfterExit=yes +ExecStart=nft -f /etc/mesh/guard.nft +ExecReload=nft -f /etc/mesh/guard.nft +ExecStop=nft delete table inet mesh_guard + +[Install] +WantedBy=multi-user.target +` + +func TestTheGuardUnitIsExactlyThisUnit(t *testing.T) { + if got := guardUnitText(); got != goldenGuardUnit { + t.Fatalf("the guard's unit changed:\n%s", got) + } +} + +func TestTheGuardRefusesOnlyWhatIsAddressedToThisMachine(t *testing.T) { + // A machine that routes for others — a predecessor's private-network hub — must not have a + // packet for another machine's database port refused (novox/hq ADR 0103). + for _, line := range strings.Split(AsGuard([]int{5432}), "\n") { + if strings.Contains(line, " drop") && !strings.HasPrefix(strings.TrimSpace(line), "fib daddr type local ") { + t.Errorf("a refusal matches packets not addressed to this machine: %q", line) + } + } +} + func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) { r := producedBundle(t) p := FoundationPorts{Store: 5433, Management: 15673}