Delete a forwarded opening the way ufw accepts it, and read a fresh machine's resolver as not in use — both measured on a lab machine (hq ADR 0100)
This commit is contained in:
@@ -10,13 +10,11 @@ import (
|
||||
"github.com/novox/mesh-host/internal/store"
|
||||
)
|
||||
|
||||
// quietUDP are processes whose UDP sockets every fresh machine has — name resolution, address
|
||||
// configuration, time — and which serve nobody. ss names a process by its first fifteen characters,
|
||||
// so both spellings are here.
|
||||
//
|
||||
// **Still to be measured** (novox/hq ADR 0100): this list is what a fresh machine is expected to
|
||||
// hold, and it must be checked against a freshly installed lab machine before it is trusted.
|
||||
var quietUDP = map[string]bool{
|
||||
// quiet are the processes every fresh machine runs that serve nobody: name resolution (whose
|
||||
// link-local resolver listens on TCP as well as UDP, on every address), address configuration and
|
||||
// time. ss names a process by its first fifteen characters, so both spellings are here. Measured
|
||||
// on a freshly installed lab machine (testdata/fresh-machine-listeners.txt): these and nothing else.
|
||||
var quiet = map[string]bool{
|
||||
"systemd-resolved": true, "systemd-resolve": true,
|
||||
"systemd-networkd": true, "systemd-network": true,
|
||||
"systemd-timesyncd": true, "systemd-timesyn": true,
|
||||
@@ -24,8 +22,8 @@ var quietUDP = map[string]bool{
|
||||
}
|
||||
|
||||
// InUse says what makes this machine a machine in use (novox/hq ADR 0100): every running container
|
||||
// no host made, and every socket listening on an address other than loopback that is not ssh's — a
|
||||
// UDP one only when it is held by something other than what every fresh machine runs. ours names
|
||||
// no host made, and every socket listening on an address other than loopback that is neither ssh's
|
||||
// nor held by what every fresh machine runs. ours names
|
||||
// what the mesh itself runs, which a re-run of genesis finds and does not count.
|
||||
func InUse(ctx context.Context, run Runner, ours func(name string) bool) ([]string, []reachable.Reach, error) {
|
||||
var containers []string
|
||||
@@ -61,9 +59,9 @@ func counts(r reachable.Reach) bool {
|
||||
}
|
||||
switch r.Protocol {
|
||||
case "tcp":
|
||||
return r.By != "sshd" && !(r.By == "" && r.Port == 22)
|
||||
return r.By != "sshd" && !(r.By == "" && r.Port == 22) && !quiet[r.By]
|
||||
case "udp":
|
||||
return !quietUDP[r.By]
|
||||
return !quiet[r.By]
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user