diff options
Diffstat (limited to 'packaging/build/build-node.sh')
| -rwxr-xr-x | packaging/build/build-node.sh | 16 |
1 files changed, 12 insertions, 4 deletions
diff --git a/packaging/build/build-node.sh b/packaging/build/build-node.sh index 9ad4968..bd81096 100755 --- a/packaging/build/build-node.sh +++ b/packaging/build/build-node.sh @@ -75,12 +75,20 @@ cp "$REPO/packaging/systemd/meshbay-node.service" \ cp "$REPO/packaging/systemd/meshbay-node-user.service" \ "$ROOT/usr/lib/systemd/user/meshbay-node.service" -# --- Firewall profile --------------------------------------------------------- -# UFW (Ubuntu/Debian) — carries the "MeshBay Cast" LAN-casting profile only. -# The node's own admin surface is a loopback API (127.0.0.1, token-gated) and -# is never firewall-exposed, so it ships no profile. +# --- Firewall profiles -------------------------------------------------------- +# The node's admin surface is a loopback API (127.0.0.1, token-gated) and is +# never firewall-exposed. Its *peer* traffic is: WebRTC binds an ephemeral UDP +# port per connection, and a peer that publishes an unroutable address — every +# browser does, as an mDNS .local name aioice cannot resolve — can only be +# reached if it calls the node. A node refusing unsolicited inbound UDP is +# therefore unreachable from browsers on its own LAN. Both profiles are passive: +# packaged, not activated, and meant to be scoped to a LAN zone/source. mkdir -p "$ROOT/etc/ufw/applications.d" cp "$REPO/packaging/firewall/ufw/meshbay" \ "$ROOT/etc/ufw/applications.d/" +mkdir -p "$ROOT/usr/lib/firewalld/services" +cp "$REPO/packaging/firewall/firewalld/meshbay-node.xml" \ + "$ROOT/usr/lib/firewalld/services/" + echo "==> meshbay-node staging ready at $ROOT" |