mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-28 09:39:05 +02:00
[management] Scope the change to the private-capability check
The PR grew past its purpose. What it needs to do is refuse to bootstrap an agent network endpoint onto a cluster that cannot serve it, which is the private capability check on the picked cluster. Everything that accreted around it — canonicalising proxy addresses at connect, refusing another account's cluster or a host another account pinned, withdrawing a claim lost to a concurrent one, folding casing on migrated settings rows — is security work in its own right and moves to follow-up PRs, where each can be reviewed against its own threat rather than as a rider on this one. This restores main's version of every file outside that purpose and reduces the validation to: a cluster the account can see must have a live embedded proxy, and a cluster management holds no row for stays pinnable (address-first). The e2e test and the fixture seeds are unchanged. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sa3DsBDP3VciAi4PPG17L6
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
4ed71f8987
commit
5502ea08ac
@@ -1,7 +1,6 @@
|
||||
package proxy
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"time"
|
||||
)
|
||||
|
||||
@@ -10,25 +9,6 @@ const (
|
||||
StatusDisconnected = "disconnected"
|
||||
)
|
||||
|
||||
// ErrClusterAddressUnavailable is returned by Manager.Connect when the cluster
|
||||
// address turns out to be claimed by someone else once the proxy's own row is
|
||||
// written: a conflicting proxy row, or another account's agent network gateway
|
||||
// pinned to the address. The row has been withdrawn by then, and the caller
|
||||
// reports the address as taken exactly as if the pre-write check had caught it.
|
||||
//
|
||||
// Both kinds of claim are made the same way, write then re-read then withdraw,
|
||||
// and the re-read is the whole mechanism. Each side's availability check and
|
||||
// its write are separate autocommit statements, so two concurrent claimants
|
||||
// can each pass their check with neither row committed yet. Because both write
|
||||
// before they re-read, of two concurrent claims at least one re-reads after
|
||||
// the other has committed and backs off; each statement sees every commit
|
||||
// before it on sqlite, postgres and mysql alike. Both may back off, which
|
||||
// costs a retry; neither keeps a claim the other holds. No lock spans the
|
||||
// proxies and settings tables portably, and a claims table would be more
|
||||
// machinery than the property needs. The gateway side of the same protocol is
|
||||
// agentnetwork's confirmGatewayClusterOwnership.
|
||||
var ErrClusterAddressUnavailable = errors.New("cluster address is not available")
|
||||
|
||||
// Capabilities describes what a proxy can handle, as reported via gRPC.
|
||||
// Nil fields mean the proxy never reported this capability.
|
||||
type Capabilities struct {
|
||||
|
||||
Reference in New Issue
Block a user