Accept intra-zone traffic between different interfaces #37

Merged
benvin merged 2 commits from benvin/intrazone-multi-iface into main 2026-10-09 23:10:48 +11:00
Member

Shorewall accepts traffic between different interfaces of the same zone unless an explicit zone zone (or all+) policy overrides it; routeback only governs same-interface traffic. tomswall emits only routeback accepts and skips explicit zone zone policies, so e.g. lxdbr0 to docker0 in zone lxd hits the forward drop.

  • emit implicit forward accepts between distinct interfaces of a zone, wildcards included
  • honour explicit zone zone policies in place of the implicit accept
  • keep same-interface intra-zone traffic governed by routeback
Shorewall accepts traffic between different interfaces of the same zone unless an explicit `zone zone` (or `all+`) policy overrides it; routeback only governs same-interface traffic. tomswall emits only routeback accepts and skips explicit `zone zone` policies, so e.g. lxdbr0 to docker0 in zone `lxd` hits the forward drop. - emit implicit forward accepts between distinct interfaces of a zone, wildcards included - honour explicit `zone zone` policies in place of the implicit accept - keep same-interface intra-zone traffic governed by routeback
unkin-agent added 1 commit 2026-10-09 22:45:55 +11:00
Accept intra-zone traffic between different interfaces
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
96a1ba8351
Author
Member
  • internal/nftables/compiler.go:863 — fw fw <action> now counts as explicitIntra; with sz==dz==fw, selectChain gives input and both ifaces are "", so it emits an unconditional input rule (all input accepted or dropped, ahead of every later net fw policy). Previously skipped → exclude the firewall zone from explicitIntra (and from overridden), and add a test with fw fw ACCEPT/DROP.
- internal/nftables/compiler.go:863 — `fw fw <action>` now counts as explicitIntra; with sz==dz==fw, selectChain gives `input` and both ifaces are "", so it emits an unconditional input rule (all input accepted or dropped, ahead of every later `net fw` policy). Previously skipped → exclude the firewall zone from explicitIntra (and from `overridden`), and add a test with `fw fw ACCEPT`/`DROP`.
unkin-agent added 1 commit 2026-10-09 22:48:35 +11:00
Skip fw->fw policies and treat dest-side + as intra-zone override
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ecc349cb6f
Author
Member

No findings.

No findings.
benvin merged commit 70df237121 into main 2026-10-09 23:10:48 +11:00
benvin deleted branch benvin/intrazone-multi-iface 2026-10-09 23:10:48 +11:00
Sign in to join this conversation.