The two-node bed stocks the packet filter's seat runtime
The filter module now serves its verbs from a runtime the mesh builds (novox/hq ADR 0170), and a bed registered its raw manifest, which the mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the filter helper registers the module through the stocked image.
This commit is contained in:
@@ -346,7 +346,7 @@ test("both machines join it, and the token is all they need", { skip, timeout: 9
|
||||
await new Promise((r) => setTimeout(r, 3000));
|
||||
}
|
||||
await new Promise((r) => setTimeout(r, 5000));
|
||||
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, must, mesh, on });
|
||||
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, held, must, mesh, on });
|
||||
|
||||
// **The laptop makes its tunnel key, and the token is issued for it.** The hub is told the key
|
||||
// before the token is shown, so the tunnel answers the first time the laptop knocks.
|
||||
@@ -409,7 +409,7 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou
|
||||
// The anchor's derived filter, admitting the hub's port — what genesis does on the control-node,
|
||||
// and what a bed raised from the bundle must do itself (ADR 0088). Until it is, the base filter
|
||||
// keeps the hub closed and nothing on the laptop reaches anchor over the private network.
|
||||
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, must, mesh, on });
|
||||
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, held, must, mesh, on });
|
||||
|
||||
const onConsumer = (await must("laptop", `cat /etc/meshboard/database.password`)).trim();
|
||||
// Named after the machine *and* the module, because a consumer is both (novox/hq
|
||||
|
||||
Reference in New Issue
Block a user