Guard only packets addressed to this machine, and load the guard before the network and stop it only at shutdown (hq ADR 0103)

This commit is contained in:
2026-09-22 18:00:54 +02:00
parent 1e0c6a3516
commit 14b3ffbd40
2 changed files with 43 additions and 4 deletions
+6 -3
View File
@@ -36,7 +36,8 @@ const (
// by default; it refuses the ports except from the machine itself — its loopback and the container
// runtime's own networks — and from the private network, known by the interface a packet arrives
// on and never by its source address; at prerouting, ahead of the runtime's destination
// translation, in the inet family so both address families.
// translation, in the inet family so both address families. It matches only packets addressed to
// this machine: what the machine routes for others is never its business (novox/hq ADR 0103).
//
// Character for character the controller's (mesh-controller internal/catalogue AsGuard); a test
// on each side holds its copy to the same golden text.
@@ -53,7 +54,7 @@ func AsGuard(ports []int) string {
b.WriteString("table inet mesh_guard {\n")
b.WriteString("\tchain prerouting {\n")
b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n")
fmt.Fprintf(&b, "\t\tiifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
fmt.Fprintf(&b, "\t\tfib daddr type local iifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
"iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", "))
b.WriteString("\t}\n")
b.WriteString("}\n")
@@ -65,8 +66,10 @@ func AsGuard(ports []int) string {
func guardUnitText() string {
return "[Unit]\n" +
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
"Before=network-pre.target\n" +
"DefaultDependencies=no\n" +
"Wants=network-pre.target\n" +
"Before=network-pre.target shutdown.target\n" +
"Conflicts=shutdown.target\n" +
"\n" +
"[Service]\n" +
"Type=oneshot\n" +
+37 -1
View File
@@ -21,7 +21,7 @@ delete table inet mesh_guard
table inet mesh_guard {
chain prerouting {
type filter hook prerouting priority raw; policy accept;
iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop
fib daddr type local iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop
}
}
`
@@ -32,6 +32,42 @@ func TestTheGuardIsExactlyThisTable(t *testing.T) {
}
}
// The same golden unit the controller's test holds its guard unit to. It is loaded before the
// network is up, so it carries no default dependencies, and it is stopped only at shutdown.
const goldenGuardUnit = `[Unit]
Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)
DefaultDependencies=no
Wants=network-pre.target
Before=network-pre.target shutdown.target
Conflicts=shutdown.target
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=nft -f /etc/mesh/guard.nft
ExecReload=nft -f /etc/mesh/guard.nft
ExecStop=nft delete table inet mesh_guard
[Install]
WantedBy=multi-user.target
`
func TestTheGuardUnitIsExactlyThisUnit(t *testing.T) {
if got := guardUnitText(); got != goldenGuardUnit {
t.Fatalf("the guard's unit changed:\n%s", got)
}
}
func TestTheGuardRefusesOnlyWhatIsAddressedToThisMachine(t *testing.T) {
// A machine that routes for others — a predecessor's private-network hub — must not have a
// packet for another machine's database port refused (novox/hq ADR 0103).
for _, line := range strings.Split(AsGuard([]int{5432}), "\n") {
if strings.Contains(line, " drop") && !strings.HasPrefix(strings.TrimSpace(line), "fib daddr type local ") {
t.Errorf("a refusal matches packets not addressed to this machine: %q", line)
}
}
}
func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
r := producedBundle(t)
p := FoundationPorts{Store: 5433, Management: 15673}