Include firewall zone in all/any rule expansion #28
Reference in New Issue
Block a user
Delete Branch "benvin/all-includes-fw"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A rule with
all/anyon either side compiles to a single global zone that selectChain always maps to forward, so rules likeACCEPT all all icmp 8never reach input or output and pings to/from the firewall are dropped. Shorewall includes$FWinall.all/anyrule specs with the firewall zone so fw pairs land in input/outputall/anyas one spec, but compileOneRule now expands it to fw pairs (all all= forward+input+output,net all/all net= 2). A ratelimit/connlimit rule on these passes the check at :384 and compiles to 2-3 independent limiters, regressing the ">1 nft rule is a compile error" guarantee → make specCount count withFirewall-expanded specs (minus the skipped fw→fw pair) so these rules are rejected.all, and no assertion on addr/iface content of the added fw rules (theall:192.0.2.0/24→fw case only counts rules) → add a ratelimit-on-allcompile-error case and check saddr/daddr is kept on the input/output rules.all+or DNAT/REDIRECT-with-allcase, though the PR body claims DNAT is unchanged → add one each.all(e.g.net,all→fw) never skips fw→fw; it emits 3 rule:0 input entries (net→fw, all→fw, fw→fw) → test each list element (split on,) in the fw→fw guard, in both compileOneRule and specCount.fw,all→fwyields fw twice) → skip the append if fwZone is already in specs.No findings.