The home server began reading "NOT the mesh alone: 1 rule set the mesh did not write refuses traffic here", and the rule set named was the mesh's own ban chain, written by the mesh's own intrusion prevention minutes earlier.
The legacy reader required every path into a chain of refusals to come from a built-in chain whose policy accepts. That chain hangs off the container runtime's user chain as well as input, and the runtime had set the forward policy to DROP. The policy is already classified where it belongs, as the runtime's, so requiring it here counted it twice. A chain is a ban when every refusal names the sources it refuses and the chain accepts nothing, which is the rule the nftables side already applied. A chain that accepts anything is still not a ban.
Fixture captured from the machine itself; the test fails against main. Also repoints the uninstalled-front-end citations to ADR 0180, which another session's renumber had left pointing at an unrelated record, and sets the service settle to nothing in tests so the suite does not pay it.
The home server began reading "NOT the mesh alone: 1 rule set the mesh did not write refuses traffic here", and the rule set named was the mesh's own ban chain, written by the mesh's own intrusion prevention minutes earlier.
The legacy reader required every path into a chain of refusals to come from a built-in chain whose policy accepts. That chain hangs off the container runtime's user chain as well as input, and the runtime had set the forward policy to DROP. The policy is already classified where it belongs, as the runtime's, so requiring it here counted it twice. A chain is a ban when every refusal names the sources it refuses and the chain accepts nothing, which is the rule the nftables side already applied. A chain that accepts anything is still not a ban.
Fixture captured from the machine itself; the test fails against main. Also repoints the uninstalled-front-end citations to ADR 0180, which another session's renumber had left pointing at an unrelated record, and sets the service settle to nothing in tests so the suite does not pay it.
The legacy reader required every path into a chain of refusals to come from a built-in whose policy
accepts. The home server's ban chain hangs off the container runtime's user chain, whose forward
policy the runtime set to DROP, so the machine reported the mesh's own intrusion prevention as a
rule set the mesh did not write. A chain is a ban when every refusal names its sources and the
chain accepts nothing — the rule the nftables side already used. A chain that accepts anything is
still not a ban. Fixture captured from the machine. The citations for the uninstalled front end move
to ADR 0180, which another session's renumber had left pointing at an unrelated record.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The home server began reading "NOT the mesh alone: 1 rule set the mesh did not write refuses traffic here", and the rule set named was the mesh's own ban chain, written by the mesh's own intrusion prevention minutes earlier.
The legacy reader required every path into a chain of refusals to come from a built-in chain whose policy accepts. That chain hangs off the container runtime's user chain as well as input, and the runtime had set the forward policy to DROP. The policy is already classified where it belongs, as the runtime's, so requiring it here counted it twice. A chain is a ban when every refusal names the sources it refuses and the chain accepts nothing, which is the rule the nftables side already applied. A chain that accepts anything is still not a ban.
Fixture captured from the machine itself; the test fails against main. Also repoints the uninstalled-front-end citations to ADR 0180, which another session's renumber had left pointing at an unrelated record, and sets the service settle to nothing in tests so the suite does not pay it.