From fafd3e2df767d568ee8671a8c0733b3e69b23d9f Mon Sep 17 00:00:00 2001 From: oqyude Date: Sat, 10 Oct 2026 16:52:09 +0300 Subject: [PATCH] docs(T3): mark nftables fix as applied + accepted MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit T3/A3 completed 2026-10-10: otreca nftables fix deployed via nixos-rebuild switch. Verification on otreca: - nft list ruleset: policy drop + 5 explicit accepts (lo, established/related, ICMP, traceroute 33434-33534, SSH on tailscale0, Xray REALITY 443) + log+drop - iptables empty (no firewall.* shadow rules) - SSH via Tailscale: works (the deploy itself proves it) - Xray REALITY on 443: listening (sapphira → otreca XHTTP intact) manifest.json T3 → completed with full notes. .decisions/index.json T3-A proposal → accepted (status, files updated to include configurations/vds.nix, notes with verification). All 17 manifest tasks now resolved (1 truly deferred was T5 backups risk — formalized as R1.9 in commit 3f5c048, marked completed 2026-10-10). T3 is the last code task — otreca config updated. Working tree: clean after this commit. --- .agent/decisions/index.json | 11 +++++------ .agent/tasks/manifest.json | 4 ++-- 2 files changed, 7 insertions(+), 8 deletions(-) diff --git a/.agent/decisions/index.json b/.agent/decisions/index.json index dd76e86..42f61c9 100644 --- a/.agent/decisions/index.json +++ b/.agent/decisions/index.json @@ -27,16 +27,15 @@ { "id": "T3-A", "title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)", - "status": "proposed", - "date": "2026-10-09", + "status": "accepted", + "date": "2026-10-10", "files": [ - ".agent/decisions/proposals/vds-nftables-fix.md" + ".agent/decisions/proposals/vds-nftables-fix.md", + "configurations/vds.nix" ], "tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"], "task": "T3", - "blocked_by": [ - "user: SSH-доступ на otreca должен быть восстановлен до apply" - ] + "notes": "Applied 2026-10-10 via nixos-rebuild switch on otreca. Verified live: nft list ruleset = policy drop + 5 accepts, iptables empty, SSH via Tailscale works, Xray REALITY on 443 listening." } ] } diff --git a/.agent/tasks/manifest.json b/.agent/tasks/manifest.json index 149214c..8ee4de0 100644 --- a/.agent/tasks/manifest.json +++ b/.agent/tasks/manifest.json @@ -50,7 +50,7 @@ "id": "T3", "title": "A3: явная финальная политика nftables на VDS", "type": "fix", - "status": "pending", + "status": "completed", "origin": "user:direct", "depends_on": [], "acceptance_criteria": [ @@ -60,7 +60,7 @@ ], "files": ["configurations/vds.nix"], "blocks": ["T11", "T12"], - "notes": "Apply deferred: требуется SSH на otreca (100.64.1.0 Tailscale и 109.248.161.5:22 оба timeout на 2026-10-10). VDS-провайдер должен восстановить доступ через KVM/IPMI/serial console. Proposal Option A в .agent/decisions/proposals/vds-nftables-fix.md готов к apply. До восстановления SSH — только README-уровень." + "notes": "Apply done 2026-10-10 (Tailscale на otreca восстановился). Option A из .agent/decisions/proposals/vds-nftables-fix.md: firewall.enable=false (R1.6 conflict resolved), lib.mkForce на allowedTCPPorts/interfaces, nftables chain input с policy drop + 5 explicit accepts (lo, established/related, ICMP, traceroute 33434-33534, SSH on tailscale0, Xray REALITY 443) + log+drop. Verified live: nft list ruleset показывает все правила, iptables пуст (нет shadow rules), SSH через Tailscale работает, Xray на 443 слушает. 2 коммита: 5796786 (основной fix) + 3deaa75 (fix allowPing — не существует на top-level networking когда firewall off)." }, { "id": "T4",