summaryrefslogtreecommitdiffstats
path: root/packaging/build/build-node.sh
diff options
context:
space:
mode:
Diffstat (limited to 'packaging/build/build-node.sh')
-rwxr-xr-xpackaging/build/build-node.sh16
1 files changed, 12 insertions, 4 deletions
diff --git a/packaging/build/build-node.sh b/packaging/build/build-node.sh
index 9ad4968..bd81096 100755
--- a/packaging/build/build-node.sh
+++ b/packaging/build/build-node.sh
@@ -75,12 +75,20 @@ cp "$REPO/packaging/systemd/meshbay-node.service" \
cp "$REPO/packaging/systemd/meshbay-node-user.service" \
"$ROOT/usr/lib/systemd/user/meshbay-node.service"
-# --- Firewall profile ---------------------------------------------------------
-# UFW (Ubuntu/Debian) — carries the "MeshBay Cast" LAN-casting profile only.
-# The node's own admin surface is a loopback API (127.0.0.1, token-gated) and
-# is never firewall-exposed, so it ships no profile.
+# --- Firewall profiles --------------------------------------------------------
+# The node's admin surface is a loopback API (127.0.0.1, token-gated) and is
+# never firewall-exposed. Its *peer* traffic is: WebRTC binds an ephemeral UDP
+# port per connection, and a peer that publishes an unroutable address — every
+# browser does, as an mDNS .local name aioice cannot resolve — can only be
+# reached if it calls the node. A node refusing unsolicited inbound UDP is
+# therefore unreachable from browsers on its own LAN. Both profiles are passive:
+# packaged, not activated, and meant to be scoped to a LAN zone/source.
mkdir -p "$ROOT/etc/ufw/applications.d"
cp "$REPO/packaging/firewall/ufw/meshbay" \
"$ROOT/etc/ufw/applications.d/"
+mkdir -p "$ROOT/usr/lib/firewalld/services"
+cp "$REPO/packaging/firewall/firewalld/meshbay-node.xml" \
+ "$ROOT/usr/lib/firewalld/services/"
+
echo "==> meshbay-node staging ready at $ROOT"