Guard only packets addressed to this machine, and load the guard before the network and stop it only at shutdown (hq ADR 0103)

This commit is contained in:
2026-09-22 18:00:54 +02:00
parent 1e0c6a3516
commit 14b3ffbd40
2 changed files with 43 additions and 4 deletions
+6 -3
View File
@@ -36,7 +36,8 @@ const (
// by default; it refuses the ports except from the machine itself — its loopback and the container // by default; it refuses the ports except from the machine itself — its loopback and the container
// runtime's own networks — and from the private network, known by the interface a packet arrives // runtime's own networks — and from the private network, known by the interface a packet arrives
// on and never by its source address; at prerouting, ahead of the runtime's destination // on and never by its source address; at prerouting, ahead of the runtime's destination
// translation, in the inet family so both address families. // translation, in the inet family so both address families. It matches only packets addressed to
// this machine: what the machine routes for others is never its business (novox/hq ADR 0103).
// //
// Character for character the controller's (mesh-controller internal/catalogue AsGuard); a test // Character for character the controller's (mesh-controller internal/catalogue AsGuard); a test
// on each side holds its copy to the same golden text. // on each side holds its copy to the same golden text.
@@ -53,7 +54,7 @@ func AsGuard(ports []int) string {
b.WriteString("table inet mesh_guard {\n") b.WriteString("table inet mesh_guard {\n")
b.WriteString("\tchain prerouting {\n") b.WriteString("\tchain prerouting {\n")
b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n") b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n")
fmt.Fprintf(&b, "\t\tiifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+ fmt.Fprintf(&b, "\t\tfib daddr type local iifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
"iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", ")) "iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", "))
b.WriteString("\t}\n") b.WriteString("\t}\n")
b.WriteString("}\n") b.WriteString("}\n")
@@ -65,8 +66,10 @@ func AsGuard(ports []int) string {
func guardUnitText() string { func guardUnitText() string {
return "[Unit]\n" + return "[Unit]\n" +
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" + "Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
"Before=network-pre.target\n" + "DefaultDependencies=no\n" +
"Wants=network-pre.target\n" + "Wants=network-pre.target\n" +
"Before=network-pre.target shutdown.target\n" +
"Conflicts=shutdown.target\n" +
"\n" + "\n" +
"[Service]\n" + "[Service]\n" +
"Type=oneshot\n" + "Type=oneshot\n" +
+37 -1
View File
@@ -21,7 +21,7 @@ delete table inet mesh_guard
table inet mesh_guard { table inet mesh_guard {
chain prerouting { chain prerouting {
type filter hook prerouting priority raw; policy accept; type filter hook prerouting priority raw; policy accept;
iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop fib daddr type local iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop
} }
} }
` `
@@ -32,6 +32,42 @@ func TestTheGuardIsExactlyThisTable(t *testing.T) {
} }
} }
// The same golden unit the controller's test holds its guard unit to. It is loaded before the
// network is up, so it carries no default dependencies, and it is stopped only at shutdown.
const goldenGuardUnit = `[Unit]
Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)
DefaultDependencies=no
Wants=network-pre.target
Before=network-pre.target shutdown.target
Conflicts=shutdown.target
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=nft -f /etc/mesh/guard.nft
ExecReload=nft -f /etc/mesh/guard.nft
ExecStop=nft delete table inet mesh_guard
[Install]
WantedBy=multi-user.target
`
func TestTheGuardUnitIsExactlyThisUnit(t *testing.T) {
if got := guardUnitText(); got != goldenGuardUnit {
t.Fatalf("the guard's unit changed:\n%s", got)
}
}
func TestTheGuardRefusesOnlyWhatIsAddressedToThisMachine(t *testing.T) {
// A machine that routes for others — a predecessor's private-network hub — must not have a
// packet for another machine's database port refused (novox/hq ADR 0103).
for _, line := range strings.Split(AsGuard([]int{5432}), "\n") {
if strings.Contains(line, " drop") && !strings.HasPrefix(strings.TrimSpace(line), "fib daddr type local ") {
t.Errorf("a refusal matches packets not addressed to this machine: %q", line)
}
}
}
func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) { func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
r := producedBundle(t) r := producedBundle(t)
p := FoundationPorts{Store: 5433, Management: 15673} p := FoundationPorts{Store: 5433, Management: 15673}