You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#24 — Spec: One typed seam through which all NAT state flows
What to build
The natmap daemon reports its live NAT rules read-only through a new GET /rules endpoint, and the forwarding sync reconciles against them. The endpoint returns structured live-rule models (kind, ext_ip, int_ip, ports, proto) parsed from the daemon's own rule listing, attributed by rule comment, including multiport (--dports) rules. The typed client gains a rules() read. The forwarding sync fetches the reported rules, diffs its desired set against them, and deletes stale forwarding rules with their real attributes via the typed client. find_stale_rules and parse_dnat_rule are deleted from auto-discover. The sync's error handling is fixed: failed rule deletions are no longer silently swallowed, and a failed create no longer skips the hairpin install. Stale multiport forwarding rules are now cleaned up.
Acceptance criteria
GET /rules returns structured live rules (kind, ext_ip, int_ip, ports, proto) parsed from the daemon's rule listing, including multiport and comment attribution, distinct from GET /mappings
The typed client exposes a rules() read over the same seam
Forwarding sync fetches reported rules and deletes stale groups with their real attributes; find_stale_rules/parse_dnat_rule are deleted from auto-discover
A stale multiport forwarding rule is detected and removed (regression case that currently fails)
Forwarding sync no longer swallows delete errors, and a failed create no longer skips the hairpin
GET /rules parsing is unit-tested in the natmap crate (single-port, multiport, hairpin, port-mapping); forwarding reconcile is unit-tested against an in-memory natmap adapter
Full workspace builds and all existing unit tests pass
Parent
#24 — Spec: One typed seam through which all NAT state flows
What to build
The natmap daemon reports its live NAT rules read-only through a new
GET /rulesendpoint, and the forwarding sync reconciles against them. The endpoint returns structured live-rule models (kind, ext_ip, int_ip, ports, proto) parsed from the daemon's own rule listing, attributed by rule comment, including multiport (--dports) rules. The typed client gains arules()read. The forwarding sync fetches the reported rules, diffs its desired set against them, and deletes stale forwarding rules with their real attributes via the typed client.find_stale_rulesandparse_dnat_ruleare deleted from auto-discover. The sync's error handling is fixed: failed rule deletions are no longer silently swallowed, and a failed create no longer skips the hairpin install. Stale multiport forwarding rules are now cleaned up.Acceptance criteria
GET /rulesreturns structured live rules (kind, ext_ip, int_ip, ports, proto) parsed from the daemon's rule listing, including multiport and comment attribution, distinct fromGET /mappingsrules()read over the same seamfind_stale_rules/parse_dnat_ruleare deleted from auto-discoverGET /rulesparsing is unit-tested in the natmap crate (single-port, multiport, hairpin, port-mapping); forwarding reconcile is unit-tested against an in-memory natmap adapterBlocked by