unkin-agent
b5be665902
Match dest zone oif on output-chain rules and policies
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 22:15:24 +10:00
benvin
78afe7c242
Merge pull request 'fix: stop differential apply rewriting unchanged rules' ( #18 ) from benvin/diff-expr-equality into main
...
ci/woodpecker/tag/release Pipeline was successful
Reviewed-on: #18
v0.2.0
2026-10-03 21:24:48 +10:00
unkin-agent
1ad025a4b7
Merge remote-tracking branch 'origin/main' into benvin/diff-expr-equality
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
# Conflicts:
# internal/nftables/diff.go
2026-10-03 21:16:39 +10:00
unkin-agent
aa0d3e10c2
Merge remote-tracking branch 'origin/main' into benvin/diff-expr-equality
...
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
# Conflicts:
# internal/nftables/compiler.go
# internal/nftables/compiler_test.go
2026-10-03 21:15:27 +10:00
benvin
3687baabe5
Merge pull request 'Fix MSS clamp loading the option as an IPv6 exthdr' ( #19 ) from benvin/mss-clamp-tcpopt into main
...
Reviewed-on: #19
2026-10-03 21:15:19 +10:00
unkin-agent
abbf434af5
Merge remote-tracking branch 'origin/main' into benvin/mss-clamp-tcpopt
...
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
# Conflicts:
# internal/nftables/compiler_test.go
2026-10-03 21:14:10 +10:00
benvin
937556abeb
Merge pull request 'Add try/confirm safe-apply with out-of-process revert' ( #17 ) from benvin/safe-apply into main
...
Reviewed-on: #17
2026-10-03 21:13:57 +10:00
benvin
a7be035456
Merge pull request 'Match any listed port or protocol in a rule' ( #15 ) from benvin/multiport-multiproto into main
...
Reviewed-on: #15
2026-10-03 21:13:10 +10:00
benvin
e6244d6bf0
Merge pull request 'Expand comma zone lists in rule source and dest' ( #16 ) from benvin/comma-zones into benvin/multiport-multiproto
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Reviewed-on: #16
2026-10-03 21:12:52 +10:00
unkin-agent
0b92f1c2f3
Refuse mutating commands during a try and scope reverts to the try ID
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
apply, flush and purge take the try lock and fail with ErrPending, which now
names 'tomswall revert' as the recovery after a failed automatic revert. Each
try gets an ID passed to the timer's 'revert --id', so a stale timer cannot
revert a newer try. Adds tests for Revert success/failure/stale ID and for
restoring a present table at the engine level.
2026-10-03 20:56:52 +10:00
unkin-agent
6ac03e1012
Persist try snapshot and arm a systemd revert timer
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:52:42 +10:00
unkin-agent
7f9c010e1a
Drop agent auto-revert; skip agent apply while a try is pending
2026-10-03 20:52:42 +10:00
unkin-agent
df7ebb8efe
fix: preserve rule order in diff and insert replacements in place
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:52:01 +10:00
unkin-agent
457056d58a
Pick reject type by resolved protocol number
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:51:25 +10:00
unkin-agent
8efed72c96
Match exact all/any zone tokens, skip only interface-less ip zones, keep DNAT free of rule extras, reject '!' inside address lists
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:50:36 +10:00
unkin-agent
ed3209681d
Load MSS option via tcpopt exthdr op in clamp rule
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:50:13 +10:00
unkin-agent
852d6bf2ca
Resolve common IANA protocol names and reject ports on portless protocols
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
2026-10-03 20:49:54 +10:00
unkin-agent
f522589a83
Merge remote-tracking branch 'origin/benvin/multiport-multiproto' into benvin/comma-zones
2026-10-03 20:48:31 +10:00
unkin-agent
e16d95fb63
fix: compare rule expressions by value in diff
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:48:29 +10:00
unkin-agent
9c30f1fa54
Reject unknown protocols and dports on mixed ICMP proto lists
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:47:46 +10:00
unkin-agent
ad2dd9e3e7
Merge benvin/multiport-multiproto; reject limits on zone and address lists
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:46:37 +10:00
unkin-agent
cc12c4a43a
Add try/confirm safe-apply and agent auto-revert
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:45:57 +10:00
unkin-agent
211bacd507
Expand comma zone lists in rule source and dest
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:45:32 +10:00
unkin-agent
30758855ff
Reject empty list elements, unknown ICMP types and limits on list rules
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:45:16 +10:00
unkin-agent
9976bc9190
Match any listed port or protocol instead of AND-ing them
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-10-03 20:41:42 +10:00
benvin
410109515e
Merge pull request 'ci: switch Go toolchain steps to gobuilder + shared S3 cache' ( #14 ) from benvin/gocache into main
...
Reviewed-on: #14
2026-10-02 23:56:29 +10:00
unkin-agent
27504777f8
ci: switch Go toolchain steps to gobuilder + shared S3 cache
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
Cut CI time/network by caching go build/vet/test artifacts in S3.
- bump build/test/pre-commit/release(test,build) to
artifactapi.../gobuilder:0.1.2-alma9
- wire GOCACHEPROG via go-cache-plugin with an absolute cache dir
- add GOCACHE_* env (ci-tomswall prefix) and AWS creds from org secrets
- leave rpm package/upload steps untouched (no Go toolchain)
2026-10-02 23:53:13 +10:00
benvin
fff9967da0
Merge pull request 'Agent: translate blrules/conntrack/secmarks/vars' ( #8 ) from benvin/agent-longtail-global2 into main
...
ci/woodpecker/tag/release Pipeline was successful
Reviewed-on: #8
v0.1.0
2026-07-26 16:56:25 +10:00
benvin
4b703f854c
Merge pull request 'Agent: translate traffic-control long-tail (mangle/accounting/tc_*)' ( #7 ) from benvin/agent-longtail-tc into main
...
Reviewed-on: #7
2026-07-26 16:55:32 +10:00
benvin
8ae09c0941
Agent: translate blrules/conntrack/secmarks/vars
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Map the rendered global-compiled tail into native config.Blrules/Conntrack/
Secmarks/Vars.
2026-07-26 16:07:28 +10:00
benvin
6d16035a0b
Agent: translate traffic-control long-tail (mangle/accounting/tc_*)
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Map the rendered mangle/accounting/tc_* sections into native tomswall config.
2026-07-26 15:57:05 +10:00
benvin
09f39ec9fe
Merge pull request 'Agent: translate per-device L2/misc long-tail' ( #6 ) from benvin/agent-longtail-l2 into main
...
Reviewed-on: #6
2026-07-26 15:46:07 +10:00
benvin
b94cb96510
Agent: translate per-device L2/misc long-tail
...
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Map the rendered tunnels/stopped_rules/proxy_arp/proxy_ndp/arp_rules/maclist
sections into native tomswall config.
2026-07-26 15:19:09 +10:00
benvin
9fd300652f
Merge pull request 'Agent: translate per-device routing long-tail' ( #5 ) from benvin/agent-longtail-routing into main
...
Reviewed-on: #5
2026-07-26 15:09:15 +10:00
benvin
59e8320dda
Agent: translate per-device routing long-tail (hosts/providers/routes/routing_rules)
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
Map the rendered hosts/providers/routes/routing_rules sections into native
tomswall config (config.Host/Provider/StaticRoute/RoutingRule). The route's
egress interface (oif) maps to StaticRoute.Device.
2026-07-26 13:02:17 +10:00
benvin
17b2130047
Merge pull request 'Agent: translate the NAT tier into native config' ( #4 ) from benvin/agent-nat into main
...
Reviewed-on: #4
2026-07-21 22:30:10 +10:00
benvin
06928bc150
Agent: translate the NAT tier into native config
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
The agent now maps the rendered NAT sections into native tomswall config:
- snat/masquerade -> config.SNAT, expanding a rendered rule's egress interface
list and source CIDRs into one native rule per (egress, source) pair (a native
SNAT rule takes a single dest interface); carries address/probability.
- netmap -> config.Netmap (from_net/to_net -> net1/net2 on the resolved interface).
- 1:1 nat -> config.StaticNAT.
Unit-tested end to end from RenderedConfig to config.Config.
2026-07-21 22:21:24 +10:00
benvin
6f1ac9a1ae
Merge pull request 'Agent: report the FIB for reachability scoping' ( #3 ) from benvin/agent-fib into main
...
Reviewed-on: #3
2026-07-20 22:40:25 +10:00
benvin
a739d87597
Merge pull request 'Add release machinery: version bump, nfpm RPM, release-on-tag' ( #2 ) from benvin/release-machinery into main
...
Reviewed-on: #2
2026-07-20 22:39:21 +10:00
benvin
66265764df
Agent: report the FIB for reachability scoping
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
The agent now collects the device's reachable prefixes from the kernel FIB
(including FRR-installed routes) via 'ip route show' / 'ip -6 route show' and
reports them to the control plane (POST /devices/{name}/routes) alongside its
status. tomswallapi uses these to scope which routers enforce a rule. Route
parsing (default routes, ECMP nexthop lines, route-type keywords, host routes,
v4/v6) is unit-tested; collection degrades to nil without iproute2.
2026-07-20 22:37:24 +10:00
benvin
a3b51018a9
Add release machinery: version bump, nfpm RPM, release-on-tag pipeline
...
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
- Makefile: add make patch|minor|major (tag + push), dist-build, completions,
and rpm/rpm-package targets.
- packaging/nfpm.yaml + scripts/build-rpm.sh: package the tomswall binary with
bash/zsh completions, the example config, and a systemd agent unit into an RPM.
- packaging/tomswall-agent.service + agent.env: run `tomswall agent` as a
systemd service (CAP_NET_ADMIN/CAP_NET_RAW), configured via /etc/tomswall/agent.env.
- .woodpecker/release.yaml: on v* tag, test -> build -> package RPM -> PUT to the
artifactapi rpm-internal repo. Matches node-lookup conventions.
2026-07-20 22:30:57 +10:00
benvin
5116fd83b4
Merge pull request 'Establish tomswall codebase and add the control-plane agent' ( #1 ) from benvin/agent into main
...
Reviewed-on: #1
2026-07-20 22:24:44 +10:00
benvin
174b2f93b9
Fix end-of-file newline (pre-commit)
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2026-07-20 22:19:11 +10:00
unkinben
9993c36d74
Merge Gitea repo initialization
ci/woodpecker/pr/pre-commit Pipeline failed
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
2026-07-20 22:12:04 +10:00
benvin
f61773ac88
Add PR CI pipelines (build, test, pre-commit)
2026-07-20 22:12:04 +10:00
benvin
e0f54ef320
Add tomswall agent (control-plane pull mode)
...
Add `tomswall agent`: it pulls this device's compiled config from tomswallapi,
differentially applies it, and reports the applied generation. It caches the
last known-good config and, when the control plane is unreachable, keeps
applying that cache — it never fails closed.
- internal/agent: rendered-config types, HTTP client (fetch + status report),
on-disk cache, on-device DNS resolver for dns sets (honors the device's
configured resolver, fail-safe on lookup failure), and the pull-apply-report
loop behind a mockable Applier.
- Translate the interface-agnostic, address-matched rendered model into native
tomswall config using the "all:<cidr>" any-interface source/dest form, reusing
the existing differential engine. Named-set members are inlined as concrete
addresses (native nft set references are a tracked follow-up).
- cmd/tomswall: wire the `agent` subcommand (flags + TOMSWALL_* env, --once).
- Unit tests: translation, cache, and the don't-fail-closed fallback loop.
- Add DESIGN.md documenting the control-plane architecture.
2026-07-20 20:05:49 +10:00
gitadmin
d445ef5a01
Initial commit
2026-07-02 23:02:58 +10:00
unkinben
8d9a76c751
Add comprehensive nftables compiler with shorewall feature parity
...
Rewrites the compiler from ~440 to ~1700 lines covering all major shorewall
firewall features: loopback, conntrack fast-path, anti-spoof, DHCP, intra-zone,
blacklist/whitelist, conntrack notrack, tunnels (13 types), rules with sections,
DNAT/redirect, SNAT/masquerade, static NAT, policies with zone exclusions,
MSS clamping, rate limiting, connection limiting, negated addresses, ICMP type
matching, TCP RST reject, user/UID matching, mark match/set, NFQUEUE, NONAT,
and policy-level rate/conn limiting.
Adds full config types for all shorewall subsystems (mangle, accounting, maclist,
netmap, providers, tunnels, conntrack, blrules, proxyarp/ndp, routes, tc, secmarks),
shorewall migration tooling, expanded CLI commands, expression-level diff engine,
and 49 unit tests.
2026-07-01 23:56:44 +10:00
unkinben
2a3eb3b04d
Initial scaffold for tomswall
...
Spiritual successor to shorewall — manages nftables directly via
google/nftables. Reads a single YAML config covering zones, interfaces,
hosts, policy, rules, snat, and named portgroups. Computes differential
changes against the running nftables state and applies them atomically.
Supports detecting and purging rules added outside of tomswall.
2026-06-28 23:43:16 +10:00