Guard the broker's plaintext port too at an adopted genesis: the filter admits it from the private network only (hq ADR 0103)

This commit is contained in:
2026-09-22 18:01:14 +02:00
parent 14b3ffbd40
commit c989b57439
2 changed files with 12 additions and 6 deletions
+8 -4
View File
@@ -103,8 +103,11 @@ type AdoptedRewrite struct {
} }
// RewriteAdopted makes the produced bundle one for an adopted machine: the foundation's own filter // RewriteAdopted makes the produced bundle one for an adopted machine: the foundation's own filter
// taken out, and the mesh's guard put in its place, guarding the store's and the broker's // taken out, and the mesh's guard put in its place, guarding on this node the store's port, the
// management ports on this node. The nftables package stays: the guard is loaded with it, and // broker's management port and the broker's plaintext port. The last is published on every
// interface and the foundation's filter admits it from the private network only, so a found
// firewall that filters only incoming traffic would leave it reachable from anywhere (novox/hq ADR
// 0103). Every one is a port of a module genesis takes. The nftables package stays: the guard is loaded with it, and
// installing a package loads no table. Openings are not the bundle's — the first push declares // installing a package loads no table. Openings are not the bundle's — the first push declares
// them, once there is a controller to derive them. // them, once there is a controller to derive them.
func RewriteAdopted(r *Rewritten, p FoundationPorts) (AdoptedRewrite, error) { func RewriteAdopted(r *Rewritten, p FoundationPorts) (AdoptedRewrite, error) {
@@ -122,11 +125,12 @@ func RewriteAdopted(r *Rewritten, p FoundationPorts) (AdoptedRewrite, error) {
out.Removed = append(out.Removed, id) out.Removed = append(out.Removed, id)
} }
out.Guarded = []int{p.Store, p.Management} out.Guarded = []int{p.Store, p.Management, p.AMQP}
var text bytes.Buffer var text bytes.Buffer
text.WriteString(",\n // The mesh's guard (novox/hq ADR 0100): this machine is adopted, so its own firewall\n" + text.WriteString(",\n // The mesh's guard (novox/hq ADR 0100): this machine is adopted, so its own firewall\n" +
" // stays in force and the foundation's filter is not loaded. The guard only refuses: the\n" + " // stays in force and the foundation's filter is not loaded. The guard only refuses: the\n" +
" // store's and the broker's management ports, except from the machine and the private network.") " // store's port and the broker's management and plaintext ports, except from the machine and\n" +
" // the private network.")
for _, res := range guardResources(out.Guarded) { for _, res := range guardResources(out.Guarded) {
var one bytes.Buffer var one bytes.Buffer
enc := json.NewEncoder(&one) enc := json.NewEncoder(&one)
+4 -2
View File
@@ -70,7 +70,7 @@ func TestTheGuardRefusesOnlyWhatIsAddressedToThisMachine(t *testing.T) {
func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) { func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
r := producedBundle(t) r := producedBundle(t)
p := FoundationPorts{Store: 5433, Management: 15673} p := FoundationPorts{Store: 5433, Management: 15673, AMQP: 5773}
if _, err := RewritePorts(&r, p, ""); err != nil { if _, err := RewritePorts(&r, p, ""); err != nil {
t.Fatal(err) t.Fatal(err)
} }
@@ -101,7 +101,9 @@ func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
if len(guards) != 1 { if len(guards) != 1 {
t.Fatalf("%d guard table(s)", len(guards)) t.Fatalf("%d guard table(s)", len(guards))
} }
if !strings.Contains(guards[0].Content, "tcp dport { 5433, 15673 } drop") { // The store's, the broker's plaintext and its management port: each one the filter admits
// from the private network only (novox/hq ADR 0103).
if !strings.Contains(guards[0].Content, "tcp dport { 5433, 5773, 15673 } drop") {
t.Errorf("the guard does not refuse this node's ports: %s", guards[0].Content) t.Errorf("the guard does not refuse this node's ports: %s", guards[0].Content)
} }
if strings.Count(guards[0].Content, "accept") != 1 || !strings.Contains(guards[0].Content, "policy accept") { if strings.Count(guards[0].Content, "accept") != 1 || !strings.Contains(guards[0].Content, "policy accept") {