The home segment moves off 192.168.1.0/24

It is the commonest home LAN range there is, so on an ordinary workstation the
lab's private segment and the machine's own network are the same addresses. The
scenario routes an egress machine explicitly and marks the rest unreachable, so
nothing leaked — but that guard was carrying the whole weight of a collision
nobody chose, and a guard is a bad place for that.

10.99.1.0/24 is still RFC 1918, so the bed still models a home LAN behind an
access point. It is simply far from what this kind of machine already has:
192.168.1 is the LAN, 172.16-31 and 192.168.16-95 are container bridges, and
10.10/10.42/10.208 are a tunnel, the mesh overlay and the virtualisation daemon.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-11 00:00:19 +02:00
parent a4c2a9b90b
commit 94e617915c
12 changed files with 48 additions and 48 deletions
+7 -7
View File
@@ -30,7 +30,7 @@ segments:
cidr: [192.0.2.0/24]
home:
kind: private
cidr: [192.168.1.0/24]
cidr: [10.99.1.0/24]
gateway:
to: hosting
address: [192.0.2.50]
@@ -41,10 +41,10 @@ machines:
at: { segment: hosting, address: [192.0.2.20] }
egress: true
ace:
at: { segment: home, address: [192.168.1.10] }
at: { segment: home, address: [10.99.1.10] }
egress: true
sealed:
at: { segment: home, address: [192.168.1.99] }
at: { segment: home, address: [10.99.1.99] }
`;
test("a machine behind a gateway still reaches the scenario through that gateway", () => {
@@ -52,16 +52,16 @@ test("a machine behind a gateway still reaches the scenario through that gateway
// handshake has to survive it. An egress machine that stopped using its gateway would be
// testing a flat network with extra steps.
const routes = scenarioRoutesFor(parseScenario(HOUSEHOLD), "ace");
assert.deepEqual(routes, [{ cidr: "192.0.2.0/24", via: "192.168.1.1" }]);
assert.deepEqual(routes, [{ cidr: "192.0.2.0/24", via: "10.99.1.1" }]);
});
test("a machine's own segment gets no route — it is already on-link", () => {
const routes = scenarioRoutesFor(parseScenario(HOUSEHOLD), "ace");
assert.ok(!routes.some((r) => r.cidr === "192.168.1.0/24"), JSON.stringify(routes));
assert.ok(!routes.some((r) => r.cidr === "10.99.1.0/24"), JSON.stringify(routes));
});
/**
* **The dangerous one.** `home` is 192.168.1.0/24 — a documentation range in spirit, an ordinary
* **The dangerous one.** `home` is 10.99.1.0/24 — a documentation range in spirit, an ordinary
* private one in fact, and very possibly the network the workstation itself is on.
*
* With one public segment there is no transit router, so novox has no path to `home` at all. Left
@@ -71,7 +71,7 @@ test("a machine's own segment gets no route — it is already on-link", () => {
*/
test("a range with no path inside the scenario is unreachable, not leaked to the uplink", () => {
const routes = scenarioRoutesFor(parseScenario(HOUSEHOLD), "novox");
assert.deepEqual(routes, [{ cidr: "192.168.1.0/24", via: null }]);
assert.deepEqual(routes, [{ cidr: "10.99.1.0/24", via: null }]);
});
test("a machine without egress is left to its default route, and states nothing", () => {