From c989b57439b6362170dc5e17ed1de80bdaf34bb5 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 18:01:14 +0200 Subject: [PATCH] Guard the broker's plaintext port too at an adopted genesis: the filter admits it from the private network only (hq ADR 0103) --- internal/bootstrap/adopted.go | 12 ++++++++---- internal/bootstrap/adopted_test.go | 6 ++++-- 2 files changed, 12 insertions(+), 6 deletions(-) diff --git a/internal/bootstrap/adopted.go b/internal/bootstrap/adopted.go index c211059..2a1ee1b 100644 --- a/internal/bootstrap/adopted.go +++ b/internal/bootstrap/adopted.go @@ -103,8 +103,11 @@ type AdoptedRewrite struct { } // RewriteAdopted makes the produced bundle one for an adopted machine: the foundation's own filter -// taken out, and the mesh's guard put in its place, guarding the store's and the broker's -// management ports on this node. The nftables package stays: the guard is loaded with it, and +// taken out, and the mesh's guard put in its place, guarding on this node the store's port, the +// broker's management port and the broker's plaintext port. The last is published on every +// interface and the foundation's filter admits it from the private network only, so a found +// firewall that filters only incoming traffic would leave it reachable from anywhere (novox/hq ADR +// 0103). Every one is a port of a module genesis takes. The nftables package stays: the guard is loaded with it, and // installing a package loads no table. Openings are not the bundle's — the first push declares // them, once there is a controller to derive them. func RewriteAdopted(r *Rewritten, p FoundationPorts) (AdoptedRewrite, error) { @@ -122,11 +125,12 @@ func RewriteAdopted(r *Rewritten, p FoundationPorts) (AdoptedRewrite, error) { out.Removed = append(out.Removed, id) } - out.Guarded = []int{p.Store, p.Management} + out.Guarded = []int{p.Store, p.Management, p.AMQP} var text bytes.Buffer text.WriteString(",\n // The mesh's guard (novox/hq ADR 0100): this machine is adopted, so its own firewall\n" + " // stays in force and the foundation's filter is not loaded. The guard only refuses: the\n" + - " // store's and the broker's management ports, except from the machine and the private network.") + " // store's port and the broker's management and plaintext ports, except from the machine and\n" + + " // the private network.") for _, res := range guardResources(out.Guarded) { var one bytes.Buffer enc := json.NewEncoder(&one) diff --git a/internal/bootstrap/adopted_test.go b/internal/bootstrap/adopted_test.go index b9e441b..cbe3a98 100644 --- a/internal/bootstrap/adopted_test.go +++ b/internal/bootstrap/adopted_test.go @@ -70,7 +70,7 @@ func TestTheGuardRefusesOnlyWhatIsAddressedToThisMachine(t *testing.T) { func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) { r := producedBundle(t) - p := FoundationPorts{Store: 5433, Management: 15673} + p := FoundationPorts{Store: 5433, Management: 15673, AMQP: 5773} if _, err := RewritePorts(&r, p, ""); err != nil { t.Fatal(err) } @@ -101,7 +101,9 @@ func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) { if len(guards) != 1 { t.Fatalf("%d guard table(s)", len(guards)) } - if !strings.Contains(guards[0].Content, "tcp dport { 5433, 15673 } drop") { + // The store's, the broker's plaintext and its management port: each one the filter admits + // from the private network only (novox/hq ADR 0103). + if !strings.Contains(guards[0].Content, "tcp dport { 5433, 5773, 15673 } drop") { t.Errorf("the guard does not refuse this node's ports: %s", guards[0].Content) } if strings.Count(guards[0].Content, "accept") != 1 || !strings.Contains(guards[0].Content, "policy accept") {