The home segment moves off 192.168.1.0/24
It is the commonest home LAN range there is, so on an ordinary workstation the lab's private segment and the machine's own network are the same addresses. The scenario routes an egress machine explicitly and marks the rest unreachable, so nothing leaked — but that guard was carrying the whole weight of a collision nobody chose, and a guard is a bad place for that. 10.99.1.0/24 is still RFC 1918, so the bed still models a home LAN behind an access point. It is simply far from what this kind of machine already has: 192.168.1 is the LAN, 172.16-31 and 192.168.16-95 are container bridges, and 10.10/10.42/10.208 are a tunnel, the mesh overlay and the virtualisation daemon. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -27,8 +27,8 @@ test("the shipped scenarios are valid", () => {
|
||||
test("a public segment on a private range is refused — the mesh would silently never form", () => {
|
||||
refuses(
|
||||
`scenario: x
|
||||
segments: { net: { kind: public, cidr: [192.168.1.0/24] } }
|
||||
machines: { a: { at: { segment: net, address: [192.168.1.1] } } }`,
|
||||
segments: { net: { kind: public, cidr: [10.99.1.0/24] } }
|
||||
machines: { a: { at: { segment: net, address: [10.99.1.1] } } }`,
|
||||
/not documentation space/,
|
||||
);
|
||||
});
|
||||
@@ -71,8 +71,8 @@ test("a gateway address must be on the PARENT segment, not the one behind it", (
|
||||
`scenario: x
|
||||
segments:
|
||||
pub: { kind: public, cidr: [192.0.2.0/24] }
|
||||
home: { kind: private, cidr: [192.168.1.0/24], gateway: { to: pub, address: [192.168.1.1], nat: [v4] } }
|
||||
machines: { a: { at: { segment: home, address: [192.168.1.9] } } }`,
|
||||
home: { kind: private, cidr: [10.99.1.0/24], gateway: { to: pub, address: [10.99.1.1], nat: [v4] } }
|
||||
machines: { a: { at: { segment: home, address: [10.99.1.9] } } }`,
|
||||
/is not within 'pub'/,
|
||||
);
|
||||
});
|
||||
@@ -120,7 +120,7 @@ test("publishing on a segment the machine is not attached to is refused", () =>
|
||||
`scenario: x
|
||||
segments:
|
||||
pub: { kind: public, cidr: [192.0.2.0/24] }
|
||||
home: { kind: private, cidr: [192.168.1.0/24], gateway: { to: pub, address: [192.0.2.5], nat: [v4] } }
|
||||
home: { kind: private, cidr: [10.99.1.0/24], gateway: { to: pub, address: [192.0.2.5], nat: [v4] } }
|
||||
machines:
|
||||
a:
|
||||
at: { segment: pub, address: [192.0.2.10] }
|
||||
@@ -176,12 +176,12 @@ test("a multi-homed machine is valid", () => {
|
||||
parseScenario(`scenario: x
|
||||
segments:
|
||||
pub: { kind: public, cidr: [192.0.2.0/24] }
|
||||
home: { kind: private, cidr: [192.168.1.0/24], gateway: { to: pub, address: [192.0.2.5], nat: [v4] } }
|
||||
home: { kind: private, cidr: [10.99.1.0/24], gateway: { to: pub, address: [192.0.2.5], nat: [v4] } }
|
||||
machines:
|
||||
border:
|
||||
at:
|
||||
- { segment: pub, address: [192.0.2.60] }
|
||||
- { segment: home, address: [192.168.1.2] }`),
|
||||
- { segment: home, address: [10.99.1.2] }`),
|
||||
);
|
||||
});
|
||||
|
||||
@@ -206,7 +206,7 @@ segments:
|
||||
cidr: [198.51.100.0/24, "2001:db8:b::/48"]
|
||||
home:
|
||||
kind: private
|
||||
cidr: [192.168.1.0/24]
|
||||
cidr: [10.99.1.0/24]
|
||||
gateway: { to: isp, address: [198.51.100.7, "2001:db8:b::7"], nat: [v4], forwardable: true, mapping_ttl: 120s }
|
||||
devices:
|
||||
kind: private
|
||||
@@ -236,7 +236,7 @@ segments:
|
||||
cidr: [198.51.100.0/24]
|
||||
home:
|
||||
kind: private
|
||||
cidr: [192.168.1.0/24]
|
||||
cidr: [10.99.1.0/24]
|
||||
gateway: { to: isp, address: [198.51.100.7], nat: [v4], forwardable: true }
|
||||
devices:
|
||||
kind: private
|
||||
|
||||
Reference in New Issue
Block a user