Group 7's host half (hq ADR 0168; issues 143, 144).
What filters the machine.firewall.Filters classifies every nftables table and legacy iptables chain that refuses traffic with an owner: mesh, found-firewall, runtime (the runtime's own chains, its forward policy, its raw guard), ban (a refusal naming the sources it refuses, in a chain accepting nothing — now also when reached through the runtime's user chain), or other. The runtime's user chain is other: that is where both predecessors kept their rules, in the legacy filter on the home server and invisible to the mesh. Reported in every apply's report as filters, adopted or converged, with the found firewall's state (found_firewall: active, retired by mesh or found-inactive) for a converged machine. A change in either is worth an unasked report. Fixtures are rulesets captured from three machines of this mesh.
Convergence is a state the host keeps.retireFirewall runs on every converged apply: a found firewall enabled again is retired again and said; a reconcile that finds it inactive records retired_by: found-inactive, never that the mesh did it; a retirement the mesh began and did not finish (the forward-policy restore failed) is finished; a step skipped after a failed apply is said in the report's firewall line.
Adoption's threshold does not move.Detect still refuses a firewall nobody speaks and still tolerates a refusing rule in the runtime's user chain, which is reported instead.
Full suite green (20 packages). The controller reads reports leniently, so this may roll first; the matching mesh-controller branch records and shows what it says.
Group 7's host half (hq ADR 0168; issues 143, 144).
- **What filters the machine.** `firewall.Filters` classifies every nftables table and legacy iptables chain that refuses traffic with an owner: `mesh`, `found-firewall`, `runtime` (the runtime's own chains, its forward policy, its raw guard), `ban` (a refusal naming the sources it refuses, in a chain accepting nothing — now also when reached through the runtime's user chain), or `other`. The runtime's user chain is `other`: that is where both predecessors kept their rules, in the legacy filter on the home server and invisible to the mesh. Reported in every apply's report as `filters`, adopted or converged, with the found firewall's state (`found_firewall`: active, retired by `mesh` or `found-inactive`) for a converged machine. A change in either is worth an unasked report. Fixtures are rulesets captured from three machines of this mesh.
- **Convergence is a state the host keeps.** `retireFirewall` runs on every converged apply: a found firewall enabled again is retired again and said; a reconcile that finds it inactive records `retired_by: found-inactive`, never that the mesh did it; a retirement the mesh began and did not finish (the forward-policy restore failed) is finished; a step skipped after a failed apply is said in the report's `firewall` line.
- **Adoption's threshold does not move.** `Detect` still refuses a firewall nobody speaks and still tolerates a refusing rule in the runtime's user chain, which is reported instead.
Full suite green (20 packages). The controller reads reports leniently, so this may roll first; the matching mesh-controller branch records and shows what it says.
Every table and chain that refuses traffic is reported with whose it is:
the mesh's, the found firewall's, the container runtime's own, a ban, or
other — the runtime's user chain is other, which is where both predecessors
kept their rules, in the legacy filter on one machine and invisible to the
mesh. Adoption's threshold does not move; a converged machine's report
grows by its filters and its found firewall's state.
Convergence is a state the host keeps: a found firewall enabled again is
retired again and said; a reconcile that finds it inactive records that it
was found so, never that the mesh did it; a step skipped after a failed
apply is said. A retirement the mesh began and did not finish is finished.
Fixtures are rulesets captured from three machines of the first mesh.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Group 7's host half (hq ADR 0168; issues 143, 144).
firewall.Filtersclassifies every nftables table and legacy iptables chain that refuses traffic with an owner:mesh,found-firewall,runtime(the runtime's own chains, its forward policy, its raw guard),ban(a refusal naming the sources it refuses, in a chain accepting nothing — now also when reached through the runtime's user chain), orother. The runtime's user chain isother: that is where both predecessors kept their rules, in the legacy filter on the home server and invisible to the mesh. Reported in every apply's report asfilters, adopted or converged, with the found firewall's state (found_firewall: active, retired bymeshorfound-inactive) for a converged machine. A change in either is worth an unasked report. Fixtures are rulesets captured from three machines of this mesh.retireFirewallruns on every converged apply: a found firewall enabled again is retired again and said; a reconcile that finds it inactive recordsretired_by: found-inactive, never that the mesh did it; a retirement the mesh began and did not finish (the forward-policy restore failed) is finished; a step skipped after a failed apply is said in the report'sfirewallline.Detectstill refuses a firewall nobody speaks and still tolerates a refusing rule in the runtime's user chain, which is reported instead.Full suite green (20 packages). The controller reads reports leniently, so this may roll first; the matching mesh-controller branch records and shows what it says.
ead1fbc160to627ac97d4f