Keep rule extras off the DNAT implied accept, expand all/any DNAT sources and match SPORT
This commit is contained in:
@@ -467,19 +467,24 @@ func (c *Compiler) compileOneRule(state *FirewallState, tag, srcSpec, dstSpec, p
|
|||||||
dports, sports config.PortSpec, action config.RuleAction, logLevel string,
|
dports, sports config.PortSpec, action config.RuleAction, logLevel string,
|
||||||
dnatDest, origDest string, fwZone string, section config.RuleSection) error {
|
dnatDest, origDest string, fwZone string, section config.RuleSection) error {
|
||||||
|
|
||||||
for _, src := range c.zoneSpecs(srcSpec) {
|
isDNAT := action == config.RuleDNAT || action == config.RuleRedirect
|
||||||
|
srcs := c.zoneSpecs(srcSpec)
|
||||||
|
if isDNAT {
|
||||||
|
srcs = c.dnatSourceSpecs(srcSpec, fwZone)
|
||||||
|
}
|
||||||
|
for _, src := range srcs {
|
||||||
for _, srcAddr := range splitAddrs(src.Addr) {
|
for _, srcAddr := range splitAddrs(src.Addr) {
|
||||||
if action == config.RuleDNAT || action == config.RuleRedirect {
|
if isDNAT {
|
||||||
if dnatSkipsIntrazone(srcSpec, src.Zone, dstSpec) {
|
if dnatSkipsIntrazone(srcSpec, src.Zone, dstSpec) {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if err := c.compileDNATAccept(state, tag, src.Zone, srcAddr, dstSpec, proto, dports, sports, action, fwZone, section); err != nil {
|
if err := c.compileDNATAccept(state, tag+":accept", src.Zone, srcAddr, dstSpec, proto, dports, sports, action, fwZone, section); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
for _, od := range splitAddrs(origDest) {
|
for _, od := range splitAddrs(origDest) {
|
||||||
if action == config.RuleDNAT || action == config.RuleRedirect {
|
if isDNAT {
|
||||||
if err := c.compileDNATRule(state, tag, src.Zone, srcAddr, od, dstSpec, proto, dports, action, logLevel); err != nil {
|
if err := c.compileDNATRule(state, tag, src.Zone, srcAddr, od, dstSpec, proto, dports, sports, action, logLevel); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
continue
|
continue
|
||||||
@@ -503,12 +508,29 @@ func (c *Compiler) compileOneRule(state *FirewallState, tag, srcSpec, dstSpec, p
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// dnatSkipsIntrazone mirrors shorewall: a zone list or all!x source never pairs a zone with itself unless marked "+".
|
// dnatSourceSpecs hooks DNAT per source zone like shorewall: all/any expand to every zone but fw (prerouting never sees fw traffic).
|
||||||
|
func (c *Compiler) dnatSourceSpecs(spec, fwZone string) []config.ZoneSpec {
|
||||||
|
zone, addr := splitZoneSpec(spec)
|
||||||
|
base, _, _ := strings.Cut(zone, "!")
|
||||||
|
if base = strings.TrimSuffix(base, "+"); base != "all" && base != "any" {
|
||||||
|
return c.zoneSpecs(spec)
|
||||||
|
}
|
||||||
|
var out []config.ZoneSpec
|
||||||
|
for _, z := range c.expandZoneRef(zone) {
|
||||||
|
if z != fwZone {
|
||||||
|
out = append(out, config.ZoneSpec{Zone: z, Addr: addr})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
|
// dnatSkipsIntrazone mirrors shorewall: a zone list or all/any source never pairs a zone with itself unless marked "+".
|
||||||
func dnatSkipsIntrazone(srcSpec, srcZone, dstSpec string) bool {
|
func dnatSkipsIntrazone(srcSpec, srcZone, dstSpec string) bool {
|
||||||
zones, _, _ := strings.Cut(srcSpec, ":")
|
zones, _, _ := strings.Cut(srcSpec, ":")
|
||||||
wild := isZoneExclusion(srcSpec) || strings.Contains(zones, ",")
|
base, _, _ := strings.Cut(zones, "!")
|
||||||
|
wild := base == "all" || base == "any" || strings.Contains(base, ",")
|
||||||
dstZone, _, _ := strings.Cut(dstSpec, ":")
|
dstZone, _, _ := strings.Cut(dstSpec, ":")
|
||||||
return wild && !strings.Contains(zones, "+!") && srcZone == dstZone
|
return wild && srcZone == dstZone
|
||||||
}
|
}
|
||||||
|
|
||||||
// compileDNATAccept emits the filter ACCEPT implied by DNAT/REDIRECT (shorewall's DNAT-/REDIRECT- omit it) for the translated flow.
|
// compileDNATAccept emits the filter ACCEPT implied by DNAT/REDIRECT (shorewall's DNAT-/REDIRECT- omit it) for the translated flow.
|
||||||
@@ -639,7 +661,7 @@ func (c *Compiler) compileZonePair(state *FirewallState, tag, srcZone, srcAddr,
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (c *Compiler) compileDNATRule(state *FirewallState, tag, srcZone, srcAddr, origDest, dstSpec, proto string,
|
func (c *Compiler) compileDNATRule(state *FirewallState, tag, srcZone, srcAddr, origDest, dstSpec, proto string,
|
||||||
dports config.PortSpec, action config.RuleAction, logLevel string) error {
|
dports, sports config.PortSpec, action config.RuleAction, logLevel string) error {
|
||||||
chain := "prerouting"
|
chain := "prerouting"
|
||||||
|
|
||||||
parts := strings.SplitN(dstSpec, ":", 3)
|
parts := strings.SplitN(dstSpec, ":", 3)
|
||||||
@@ -667,7 +689,7 @@ func (c *Compiler) compileDNATRule(state *FirewallState, tag, srcZone, srcAddr,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
matches, err := l4Matches(proto, dports, nil)
|
matches, err := l4Matches(proto, dports, sports)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1627,7 +1627,7 @@ func TestCompile_QueueRedirMatchKernelReadback(t *testing.T) {
|
|||||||
for _, rules := range state.Rules {
|
for _, rules := range state.Rules {
|
||||||
for _, r := range rules {
|
for _, r := range rules {
|
||||||
w, ok := want[r.Tag]
|
w, ok := want[r.Tag]
|
||||||
if !ok || r.Chain != "prerouting" && r.Tag == "rule:3" {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if got := r.Exprs[len(r.Exprs)-1]; !reflect.DeepEqual(got, w) {
|
if got := r.Exprs[len(r.Exprs)-1]; !reflect.DeepEqual(got, w) {
|
||||||
@@ -1943,6 +1943,18 @@ func TestCompile_CommaZoneLists(t *testing.T) {
|
|||||||
want: map[string][]string{"prerouting": {"iif=eth0", "iif=eth2"},
|
want: map[string][]string{"prerouting": {"iif=eth0", "iif=eth2"},
|
||||||
"forward": {"iif=eth0 oif=eth2 daddr=192.0.2.10", "iif=eth2 oif=eth2 daddr=192.0.2.10"}},
|
"forward": {"iif=eth0 oif=eth2 daddr=192.0.2.10", "iif=eth2 oif=eth2 daddr=192.0.2.10"}},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: "dnat all source expands per zone and skips fw and the target zone",
|
||||||
|
rule: config.Rule{Action: config.RuleDNAT, Source: "all", Dest: "svr:192.0.2.10", Proto: "tcp", DPort: config.PortSpec{"80"}},
|
||||||
|
want: map[string][]string{"prerouting": {"iif=eth3", "iif=eth1", "iif=eth0"},
|
||||||
|
"forward": {"iif=eth3 oif=eth2 daddr=192.0.2.10", "iif=eth1 oif=eth2 daddr=192.0.2.10", "iif=eth0 oif=eth2 daddr=192.0.2.10"}},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "dnat any+ source keeps the target zone",
|
||||||
|
rule: config.Rule{Action: config.RuleDNAT, Source: "any+", Dest: "svr:192.0.2.10", Proto: "tcp", DPort: config.PortSpec{"80"}},
|
||||||
|
want: map[string][]string{"prerouting": {"iif=eth3", "iif=eth1", "iif=eth0", "iif=eth2"},
|
||||||
|
"forward": {"iif=eth3 oif=eth2 daddr=192.0.2.10", "iif=eth1 oif=eth2 daddr=192.0.2.10", "iif=eth0 oif=eth2 daddr=192.0.2.10", "iif=eth2 oif=eth2 daddr=192.0.2.10"}},
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: "dnat to fw accepts in input",
|
name: "dnat to fw accepts in input",
|
||||||
rule: config.Rule{Action: config.RuleDNAT, Source: "net", Dest: "fw:192.0.2.1", Proto: "tcp", DPort: config.PortSpec{"80"}},
|
rule: config.Rule{Action: config.RuleDNAT, Source: "net", Dest: "fw:192.0.2.1", Proto: "tcp", DPort: config.PortSpec{"80"}},
|
||||||
@@ -2056,7 +2068,7 @@ func TestCompile_CommaZoneLists(t *testing.T) {
|
|||||||
got := map[string][]string{}
|
got := map[string][]string{}
|
||||||
for chain, rules := range state.Rules {
|
for chain, rules := range state.Rules {
|
||||||
for _, r := range rules {
|
for _, r := range rules {
|
||||||
if r.Tag == tag {
|
if r.Tag == tag || r.Tag == tag+":accept" {
|
||||||
got[chain] = append(got[chain], describeRule(r))
|
got[chain] = append(got[chain], describeRule(r))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -2263,18 +2275,79 @@ func TestCompile_DNATImpliedAccept(t *testing.T) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatalf("Compile() error: %v", err)
|
t.Fatalf("Compile() error: %v", err)
|
||||||
}
|
}
|
||||||
fwd := taggedRules(state, "forward", "rule:0")
|
fwd := taggedRules(state, "forward", "rule:0:accept")
|
||||||
if len(fwd) != 1 {
|
if len(fwd) != 1 {
|
||||||
t.Fatalf("got %d forward accepts, want 1", len(fwd))
|
t.Fatalf("got %d forward accepts, want 1", len(fwd))
|
||||||
}
|
}
|
||||||
want := append(append(append(append(append(matchIfaceName(true, "eth0"), matchIfaceName(false, "eth2")...),
|
want := append(append(append(append(append(matchIfaceName(true, "eth0"), matchIfaceName(false, "eth2")...),
|
||||||
mustExprs(t)(matchDestCIDR("192.0.2.17"))...), mustExprs(t)(l4Exprs("tcp", "8080"))...),
|
mustExprs(t)(matchDestCIDR("192.0.2.17"))...), mustExprs(t)(l4Exprs("tcp", "8080"))...),
|
||||||
matchCtBits(expr.CtKeySTATUS, ctStatusDNAT)...), &expr.Verdict{Kind: expr.VerdictAccept})
|
dnatStatusExprs...), &expr.Verdict{Kind: expr.VerdictAccept})
|
||||||
if !reflect.DeepEqual(fwd[0].Exprs, want) {
|
if !reflect.DeepEqual(fwd[0].Exprs, want) {
|
||||||
t.Errorf("forward accept = %#v, want %#v", fwd[0].Exprs, want)
|
t.Errorf("forward accept = %#v, want %#v", fwd[0].Exprs, want)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// IPS_DST_NAT = 1<<5, hard-coded so a wrong ctStatusDNAT or ct key fails here.
|
||||||
|
var dnatStatusExprs = []expr.Any{
|
||||||
|
&expr.Ct{Key: expr.CtKeySTATUS, Register: 1},
|
||||||
|
&expr.Bitwise{SourceRegister: 1, DestRegister: 1, Len: 4, Mask: binary.NativeEndian.AppendUint32(nil, 32), Xor: []byte{0, 0, 0, 0}},
|
||||||
|
&expr.Cmp{Op: expr.CmpOpNeq, Register: 1, Data: []byte{0, 0, 0, 0}},
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCompile_DNATImpliedAcceptGetsNoRuleExtras(t *testing.T) {
|
||||||
|
compile := func(r config.Rule) *FirewallState {
|
||||||
|
state, err := NewCompiler(listCfg(func(c *config.Config) {
|
||||||
|
c.Zones["svr"] = config.Zone{Type: config.ZoneIP}
|
||||||
|
c.Interfaces = append(c.Interfaces, config.Interface{Zone: "svr", Interface: "eth2"})
|
||||||
|
c.Rules = []config.Rule{r}
|
||||||
|
})).Compile()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Compile() error: %v", err)
|
||||||
|
}
|
||||||
|
return state
|
||||||
|
}
|
||||||
|
plain := config.Rule{Action: config.RuleDNAT, Source: "net", Dest: "svr:192.0.2.17", Proto: "tcp", DPort: config.PortSpec{"80"}}
|
||||||
|
extras := plain
|
||||||
|
extras.RateLimit, extras.Mark, extras.User = "10/sec:5", "0x1", "root"
|
||||||
|
want, got := compile(plain), compile(extras)
|
||||||
|
if len(taggedRules(got, "forward", "rule:0:accept")) != 1 {
|
||||||
|
t.Fatalf("want one forward accept, got %v", got.Rules["forward"])
|
||||||
|
}
|
||||||
|
if !reflect.DeepEqual(got.Rules, want.Rules) {
|
||||||
|
t.Errorf("ratelimit/mark/user changed the DNAT rules:\ngot %#v\nwant %#v", got.Rules, want.Rules)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCompile_DNATMatchesSport(t *testing.T) {
|
||||||
|
state, err := NewCompiler(listCfg(func(c *config.Config) {
|
||||||
|
c.Zones["svr"] = config.Zone{Type: config.ZoneIP}
|
||||||
|
c.Interfaces = append(c.Interfaces, config.Interface{Zone: "svr", Interface: "eth2"})
|
||||||
|
c.Rules = []config.Rule{{Action: config.RuleDNAT, Source: "net", Dest: "svr:192.0.2.17", Proto: "tcp",
|
||||||
|
DPort: config.PortSpec{"80"}, SPort: config.PortSpec{"1024"}}}
|
||||||
|
})).Compile()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Compile() error: %v", err)
|
||||||
|
}
|
||||||
|
m, err := l4Matches("tcp", config.PortSpec{"80"}, config.PortSpec{"1024"})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
for _, r := range append(taggedRules(state, "prerouting", "rule:0"), taggedRules(state, "forward", "rule:0:accept")...) {
|
||||||
|
if !containsExprs(r.Exprs, m[0].exprs) {
|
||||||
|
t.Errorf("%s rule lacks the sport match: %#v", r.Chain, r.Exprs)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func containsExprs(haystack, needle []expr.Any) bool {
|
||||||
|
for i := 0; i+len(needle) <= len(haystack); i++ {
|
||||||
|
if reflect.DeepEqual(haystack[i:i+len(needle)], needle) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
func mustExprs(t *testing.T) func([]expr.Any, error) []expr.Any {
|
func mustExprs(t *testing.T) func([]expr.Any, error) []expr.Any {
|
||||||
return func(e []expr.Any, err error) []expr.Any {
|
return func(e []expr.Any, err error) []expr.Any {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
@@ -2298,6 +2371,7 @@ func TestCompile_CommaZoneListLimitErrors(t *testing.T) {
|
|||||||
{Action: config.RuleAccept, Source: "net", Dest: "fw,lan", RateLimit: "10/sec:5"},
|
{Action: config.RuleAccept, Source: "net", Dest: "fw,lan", RateLimit: "10/sec:5"},
|
||||||
{Action: config.RuleAccept, Source: "net,lan", Dest: "fw", ConnLimit: "10"},
|
{Action: config.RuleAccept, Source: "net,lan", Dest: "fw", ConnLimit: "10"},
|
||||||
{Action: config.RuleAccept, Source: "net", Dest: "fw:192.0.2.1,198.51.100.1", RateLimit: "10/sec"},
|
{Action: config.RuleAccept, Source: "net", Dest: "fw:192.0.2.1,198.51.100.1", RateLimit: "10/sec"},
|
||||||
|
{Action: config.RuleDNAT, Source: "net,lan", Dest: "fw:192.0.2.1", RateLimit: "10/sec"},
|
||||||
} {
|
} {
|
||||||
t.Run(r.Source+">"+r.Dest, func(t *testing.T) {
|
t.Run(r.Source+">"+r.Dest, func(t *testing.T) {
|
||||||
cfg := &config.Config{
|
cfg := &config.Config{
|
||||||
|
|||||||
Reference in New Issue
Block a user