Honour shorewall INVALID_DISPOSITION and UNTRACKED_DISPOSITION #31

Merged
benvin merged 2 commits from benvin/invalid-disposition into main 2026-10-04 15:42:40 +11:00
Member

tomswall always drops ct state invalid, but shorewall applies INVALID_DISPOSITION (default CONTINUE), so migrated configs are stricter than the source and can break asymmetric ECMP/anycast flows.

  • add invalid_disposition and untracked_disposition settings (accept/drop/reject/continue)
  • map INVALID_DISPOSITION/UNTRACKED_DISPOSITION in migrate, defaulting to continue, A_ variants to their base action
  • emit no rule for continue; native configs keep invalid drop, untracked continue
tomswall always drops `ct state invalid`, but shorewall applies `INVALID_DISPOSITION` (default CONTINUE), so migrated configs are stricter than the source and can break asymmetric ECMP/anycast flows. - add `invalid_disposition` and `untracked_disposition` settings (accept/drop/reject/continue) - map `INVALID_DISPOSITION`/`UNTRACKED_DISPOSITION` in migrate, defaulting to continue, A_ variants to their base action - emit no rule for continue; native configs keep invalid drop, untracked continue
unkin-agent added 1 commit 2026-10-04 15:34:17 +11:00
honour shorewall INVALID_DISPOSITION and UNTRACKED_DISPOSITION
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
c3049e3ed4
Author
Member
  • internal/shorewall/convert.go:129 — if conf == nil { return nil } runs before the new disposition lines, so a dir with no shorewall.conf/shorewall6.conf is migrated with unset dispositions, i.e. invalid DROP, not shorewall's CONTINUE default → set InvalidDisposition/UntrackedDisposition to continue before that early return (or in convertDir) and add a test with no conf file.
  • nit: internal/config/config.go:123 — new validation branch has no test → add a case in the config tests that invalid_disposition: bogus is rejected and continue is accepted.
- internal/shorewall/convert.go:129 — `if conf == nil { return nil }` runs before the new disposition lines, so a dir with no shorewall.conf/shorewall6.conf is migrated with unset dispositions, i.e. invalid DROP, not shorewall's CONTINUE default → set `InvalidDisposition`/`UntrackedDisposition` to continue before that early return (or in convertDir) and add a test with no conf file. - nit: internal/config/config.go:123 — new validation branch has no test → add a case in the config tests that `invalid_disposition: bogus` is rejected and `continue` is accepted.
unkin-agent added 1 commit 2026-10-04 15:36:00 +11:00
default dispositions to continue before the nil-conf return; test bad disposition values
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
2ed5b958b4
Author
Member

No findings.

No findings.
benvin merged commit 200b4d3bdf into main 2026-10-04 15:42:40 +11:00
benvin deleted branch benvin/invalid-disposition 2026-10-04 15:42:41 +11:00
Sign in to join this conversation.