Guard only packets addressed to this machine, and load the guard before the network and stop it only at shutdown (hq ADR 0103)
This commit is contained in:
@@ -36,7 +36,8 @@ const (
|
|||||||
// by default; it refuses the ports except from the machine itself — its loopback and the container
|
// by default; it refuses the ports except from the machine itself — its loopback and the container
|
||||||
// runtime's own networks — and from the private network, known by the interface a packet arrives
|
// runtime's own networks — and from the private network, known by the interface a packet arrives
|
||||||
// on and never by its source address; at prerouting, ahead of the runtime's destination
|
// on and never by its source address; at prerouting, ahead of the runtime's destination
|
||||||
// translation, in the inet family so both address families.
|
// translation, in the inet family so both address families. It matches only packets addressed to
|
||||||
|
// this machine: what the machine routes for others is never its business (novox/hq ADR 0103).
|
||||||
//
|
//
|
||||||
// Character for character the controller's (mesh-controller internal/catalogue AsGuard); a test
|
// Character for character the controller's (mesh-controller internal/catalogue AsGuard); a test
|
||||||
// on each side holds its copy to the same golden text.
|
// on each side holds its copy to the same golden text.
|
||||||
@@ -53,7 +54,7 @@ func AsGuard(ports []int) string {
|
|||||||
b.WriteString("table inet mesh_guard {\n")
|
b.WriteString("table inet mesh_guard {\n")
|
||||||
b.WriteString("\tchain prerouting {\n")
|
b.WriteString("\tchain prerouting {\n")
|
||||||
b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n")
|
b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n")
|
||||||
fmt.Fprintf(&b, "\t\tiifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
|
fmt.Fprintf(&b, "\t\tfib daddr type local iifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
|
||||||
"iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", "))
|
"iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", "))
|
||||||
b.WriteString("\t}\n")
|
b.WriteString("\t}\n")
|
||||||
b.WriteString("}\n")
|
b.WriteString("}\n")
|
||||||
@@ -65,8 +66,10 @@ func AsGuard(ports []int) string {
|
|||||||
func guardUnitText() string {
|
func guardUnitText() string {
|
||||||
return "[Unit]\n" +
|
return "[Unit]\n" +
|
||||||
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
|
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
|
||||||
"Before=network-pre.target\n" +
|
"DefaultDependencies=no\n" +
|
||||||
"Wants=network-pre.target\n" +
|
"Wants=network-pre.target\n" +
|
||||||
|
"Before=network-pre.target shutdown.target\n" +
|
||||||
|
"Conflicts=shutdown.target\n" +
|
||||||
"\n" +
|
"\n" +
|
||||||
"[Service]\n" +
|
"[Service]\n" +
|
||||||
"Type=oneshot\n" +
|
"Type=oneshot\n" +
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ delete table inet mesh_guard
|
|||||||
table inet mesh_guard {
|
table inet mesh_guard {
|
||||||
chain prerouting {
|
chain prerouting {
|
||||||
type filter hook prerouting priority raw; policy accept;
|
type filter hook prerouting priority raw; policy accept;
|
||||||
iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop
|
fib daddr type local iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
`
|
`
|
||||||
@@ -32,6 +32,42 @@ func TestTheGuardIsExactlyThisTable(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The same golden unit the controller's test holds its guard unit to. It is loaded before the
|
||||||
|
// network is up, so it carries no default dependencies, and it is stopped only at shutdown.
|
||||||
|
const goldenGuardUnit = `[Unit]
|
||||||
|
Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)
|
||||||
|
DefaultDependencies=no
|
||||||
|
Wants=network-pre.target
|
||||||
|
Before=network-pre.target shutdown.target
|
||||||
|
Conflicts=shutdown.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
ExecStart=nft -f /etc/mesh/guard.nft
|
||||||
|
ExecReload=nft -f /etc/mesh/guard.nft
|
||||||
|
ExecStop=nft delete table inet mesh_guard
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
`
|
||||||
|
|
||||||
|
func TestTheGuardUnitIsExactlyThisUnit(t *testing.T) {
|
||||||
|
if got := guardUnitText(); got != goldenGuardUnit {
|
||||||
|
t.Fatalf("the guard's unit changed:\n%s", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTheGuardRefusesOnlyWhatIsAddressedToThisMachine(t *testing.T) {
|
||||||
|
// A machine that routes for others — a predecessor's private-network hub — must not have a
|
||||||
|
// packet for another machine's database port refused (novox/hq ADR 0103).
|
||||||
|
for _, line := range strings.Split(AsGuard([]int{5432}), "\n") {
|
||||||
|
if strings.Contains(line, " drop") && !strings.HasPrefix(strings.TrimSpace(line), "fib daddr type local ") {
|
||||||
|
t.Errorf("a refusal matches packets not addressed to this machine: %q", line)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
|
func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
|
||||||
r := producedBundle(t)
|
r := producedBundle(t)
|
||||||
p := FoundationPorts{Store: 5433, Management: 15673}
|
p := FoundationPorts{Store: 5433, Management: 15673}
|
||||||
|
|||||||
Reference in New Issue
Block a user