Repository navigation
Put devices named by hardware address in their rule sets - #412
Merged
Merged
Conversation
A [[clients]] entry with a mac and a rule_set now applies at every address Sable has tied to that hardware address, from the neighbor table, UniFi, or the cluster lead. An address follows whichever device used it last. The table sits beside the runtime in the handler, so a new lease or IPv6 privacy address swaps a small map instead of recompiling the block lists. A worker rebuilds it from the store after each batch of identities and each configuration change, and does nothing while no device by hardware address has a rule set. With Insights off it stays empty, so only configured addresses apply, as #240 decided. Refs #240
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Nick · project thread
Before: a device's
rule_setapplied only to[[clients]]entries that name an IP or network. A device named bymac, which is how the Insights drawer names devices, kept its rule set in config but blocked with the default policy.After: a device named by
macgets its rule set at every address Sable has tied to that hardware address, whether the tie came from the neighbor table, UniFi, or the cluster lead (so replicas in Docker work too). An address follows whichever device used it last. With Insights off, Sable doesn't tie addresses to hardware, so only configured addresses apply, as #240's Decisions say.This is PR 2 of #240. The "matched by" view in the device drawer comes with the console PR;
Handler.DeviceAddressTable()is what it will read.How
dnsserver.DeviceAddresses(address → rule set name) sits in its ownatomic.Pointeron the handler, so a new DHCP lease or IPv6 privacy address swaps a small map without recompiling the block lists. Precedence: an address named in config, then a learned address, then the most specific network.internal/app/device_rule_sets.gowraps the three identity recorders (neighbor sampler, UniFi, cluster heartbeat) and also wakes on config changes. It reads identities over the Insights lookback and walks them newest first, so each address goes to its latest device. While no device by hardware address has a rule set, it reads nothing.Benchmarks
BenchmarkPolicyDecision, 100k domains, 200k iterations, median of 5 on a shared, noisy container:TestPolicyDecisionDoesNotAllocateWithRuleSetsnow includes a learned address.Checks
go tool mage verifypasses andgofmt -l .is clean. The new worker test passes under-race -count=3.Refs #240
Generated by Claude Code