The base filter opens the bus and the registry in the input chain too

A container on the machine dialling a port the machine publishes reaches it
through the runtime's proxy — input, not forward — and the builder could not
reach the broker. The derived ruleset opens the mesh's own ports in both
chains; the base one now does the same.
This commit is contained in:
2026-09-21 12:28:57 +02:00
parent b72b71a989
commit c32eada62b
2 changed files with 7 additions and 3 deletions
+2 -1
View File
@@ -200,7 +200,8 @@ func TestTheFoundationFiltersBeforeAnythingListens(t *testing.T) {
t.Fatalf("order: filter %d loaded %d store %d broker %d", filterAt, loadedAt, storeAt, brokerAt)
}
for _, want := range []string{"policy drop", "tcp dport 22 accept", "ct original proto-dst 5671 accept",
"ct original proto-dst 5000 accept", "ip saddr 172.16.0.0/12 accept", "table inet mesh"} {
"ct original proto-dst 5000 accept", "tcp dport 5671 accept", "tcp dport 5000 accept",
"ip saddr 172.16.0.0/12 accept", "table inet mesh"} {
if !strings.Contains(rules, want) {
t.Errorf("the base filter lacks %q", want)
}