feat(mesh): app direct ports reachable over the mesh — IPv4 listeners mirrored onto [::]
The companion reaches the node at its fips0 ULA, and the web UI builds app links as http://[<ULA>]:<direct port> — but rootless-podman published ports bind 0.0.0.0 only, so every app URL was refused over the mesh (:8334 first). A reconcile loop in the backend mirrors public IPv4 listeners: any port >=1024 on 0.0.0.0 without an IPv6 any-listener gets a v6-ONLY [::] forwarder to 127.0.0.1, following /proc/net/tcp* so install/remove and hardcoded companion ports are covered without touching a single container. Purely additive: IPv4/LAN/Tor access paths are untouched, v6only listeners cannot collide with or intercept v4 traffic, and foreign IPv6 listeners win. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
6c48de20e3
commit
2ad57c63f1
@@ -22,6 +22,9 @@ iroh-swarm = ["dep:iroh", "dep:iroh-blobs"]
|
||||
[dependencies]
|
||||
# Core dependencies
|
||||
tokio = { version = "1", features = ["full"] }
|
||||
# Mesh port mirror: needs IPV6_V6ONLY on [::] listeners so they coexist with
|
||||
# the containers' own 0.0.0.0 binds (std/tokio don't expose the sockopt).
|
||||
socket2 = "0.5"
|
||||
libc = "0.2" # process-group signalling for the supervised reticulum daemon
|
||||
serde = { version = "1.0", features = ["derive"] }
|
||||
serde_json = "1.0"
|
||||
|
||||
Reference in New Issue
Block a user