Four lines of patched JavaScript, and the router VM that deleted them
Two small patches to a dependency file called ssdp.js . Four lines of changed JavaScript, total. They kept the fleet's nodes reachable from the internet, and they were the reason every incident on the fleet, for months, started with the same sentence: "the patches are gone again." The patches lived inside a Node.js dependency called @runonflux/nat-upnp . Every time the application updated itself…
A pair of small updates to a JavaScript file named ssdp.js, consisting of just four lines of revised code. These lines maintained the fleet's nodes' connectivity to the internet, and they were key to every incident on the fleet, starting with the same sentence for months: "the patches are gone again." The patches were contained within a Node.js dependency called @runonflux/nat-upnp.
Each time the application refreshed itself, frequently, the file was updated, erasing the four lines. A scheduled task would detect this within a minute and restore them. A timer paired with a brief pause would reapply them during startup. A monitoring system on the edge firewall would restart miniupnpd every two minutes, as the UPnP daemon had a tendency to lose state without any log indicating it had.
And a check every thirty minutes would confirm that the patches remained on the disk and that the UPnP mappings the daemon had negotiated were still present. These four continuous pieces of maintenance were running on seven nodes. The migration's goal was not to enhance any of these mechanisms, but rather to eliminate them.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.