Skip to content

Forwarding sync reconciles against daemon-reported live rules #26

Description

@FAZuH

Parent

#24 — Spec: One typed seam through which all NAT state flows

What to build

The natmap daemon reports its live NAT rules read-only through a new GET /rules endpoint, and the forwarding sync reconciles against them. The endpoint returns structured live-rule models (kind, ext_ip, int_ip, ports, proto) parsed from the daemon's own rule listing, attributed by rule comment, including multiport (--dports) rules. The typed client gains a rules() read. The forwarding sync fetches the reported rules, diffs its desired set against them, and deletes stale forwarding rules with their real attributes via the typed client. find_stale_rules and parse_dnat_rule are deleted from auto-discover. The sync's error handling is fixed: failed rule deletions are no longer silently swallowed, and a failed create no longer skips the hairpin install. Stale multiport forwarding rules are now cleaned up.

Acceptance criteria

  • GET /rules returns structured live rules (kind, ext_ip, int_ip, ports, proto) parsed from the daemon's rule listing, including multiport and comment attribution, distinct from GET /mappings
  • The typed client exposes a rules() read over the same seam
  • Forwarding sync fetches reported rules and deletes stale groups with their real attributes; find_stale_rules/parse_dnat_rule are deleted from auto-discover
  • A stale multiport forwarding rule is detected and removed (regression case that currently fails)
  • Forwarding sync no longer swallows delete errors, and a failed create no longer skips the hairpin
  • GET /rules parsing is unit-tested in the natmap crate (single-port, multiport, hairpin, port-mapping); forwarding reconcile is unit-tested against an in-memory natmap adapter
  • Full workspace builds and all existing unit tests pass

Blocked by

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions