The host applies the newest declaration, a file may be created once, the foundation filters first

031: a window of unacknowledged declarations is drained to the newest; the
rest are set aside and reported as superseded. 035: a file resource may say
create-once — written when absent, kept untouched when present (ADR 0087).
054: the bundle installs nftables and loads a base ruleset before the store
and broker, in the table the filter module later replaces (ADR 0088).
This commit is contained in:
2026-09-21 12:11:52 +02:00
parent d7eea1ab66
commit b72b71a989
8 changed files with 258 additions and 4 deletions
+46
View File
@@ -165,3 +165,49 @@ func TestTheBrokerAdminMarkerHasALineEnding(t *testing.T) {
}
}
}
// The foundation filters before anything listens: nftables is in place before the store, and its
// rules refuse the store's and broker's client ports from outside while keeping ssh, the bus a node
// enrols over and the registry a node pulls from (novox/hq issue 054).
func TestTheFoundationFiltersBeforeAnythingListens(t *testing.T) {
template, err := os.ReadFile("../../examples/foundation-first-node.lock")
if err != nil {
t.Skip("no example bundle beside this checkout")
}
r, err := Rewrite(template, "sha256:"+strings.Repeat("ab", 32))
if err != nil {
t.Fatal(err)
}
if _, err := RewriteRoot(&r, RootCredentials{Store: "s", Broker: "b"}); err != nil {
t.Fatal(err)
}
var filterAt, loadedAt, storeAt, brokerAt = -1, -1, -1, -1
var rules string
for i, res := range r.Declaration.Resources {
switch res.Identity() {
case "base-filter":
filterAt = i
rules = res.(*declaration.File).Content
case "base-filter-loaded":
loadedAt = i
case "store":
storeAt = i
case "broker":
brokerAt = i
}
}
if !(filterAt >= 0 && filterAt < loadedAt && loadedAt < storeAt && storeAt < brokerAt) {
t.Fatalf("order: filter %d loaded %d store %d broker %d", filterAt, loadedAt, storeAt, brokerAt)
}
for _, want := range []string{"policy drop", "tcp dport 22 accept", "ct original proto-dst 5671 accept",
"ct original proto-dst 5000 accept", "ip saddr 172.16.0.0/12 accept", "table inet mesh"} {
if !strings.Contains(rules, want) {
t.Errorf("the base filter lacks %q", want)
}
}
for _, mustNot := range []string{"5432", "5672"} {
if strings.Contains(rules, mustNot) {
t.Errorf("the base filter names %s, which must be reached from the machine and its containers only", mustNot)
}
}
}