Match zones defined by hosts entries #38

Merged
benvin merged 4 commits from benvin/hosts-zones into main 2026-10-09 23:28:55 +11:00
Member

Zones defined only by hosts entries (e.g. lan:net with lan wlo1:192.0.2.0/24) resolve to no interfaces, so the compiler skips their rules and policies, and the parent zone captures their hosts.

  • match hosts zones by interface plus address (iif/saddr as source, oif/daddr as dest) for rules, policies, DNAT, conntrack and blrules
  • exclude sub-zone hosts from the parent zone match so they classify as the sub-zone first
  • guard host addresses and exclusions with their family, splitting exclusions per family
  • honour hosts ! exclusions and keep failing closed for zones with neither interfaces nor hosts
  • parse ! exclusions and [v6] brackets in hosts and - interface zones on migrate
  • validate hosts addresses
Zones defined only by `hosts` entries (e.g. `lan:net` with `lan wlo1:192.0.2.0/24`) resolve to no interfaces, so the compiler skips their rules and policies, and the parent zone captures their hosts. - match hosts zones by interface plus address (iif/saddr as source, oif/daddr as dest) for rules, policies, DNAT, conntrack and blrules - exclude sub-zone hosts from the parent zone match so they classify as the sub-zone first - guard host addresses and exclusions with their family, splitting exclusions per family - honour hosts `!` exclusions and keep failing closed for zones with neither interfaces nor hosts - parse `!` exclusions and `[v6]` brackets in hosts and `-` interface zones on migrate - validate hosts addresses
unkin-agent added 1 commit 2026-10-09 22:48:34 +11:00
Match zones defined by hosts entries
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
695869c80b
Author
Member
  • internal/nftables/compiler.go:1333 — unguarded ip saddr/daddr != excl on an IPv6 packet reads IPv6 header bytes, so a matching packet skips the zone match. That is stricter for ACCEPT but looser for DROP/REJECT rules, blrules and DROP/REJECT policies: the packet escapes the drop and can reach a later accept (the ponytail note at :1312 is wrong that it only skips the zone) → emit the exclusion as (nfproto != fam) OR (addr != excl) per exclusion family, or reject mixed-family exclusions in validateHosts; drop the false comment.
- internal/nftables/compiler.go:1333 — unguarded `ip saddr/daddr != excl` on an IPv6 packet reads IPv6 header bytes, so a matching packet skips the zone match. That is stricter for ACCEPT but looser for DROP/REJECT rules, blrules and DROP/REJECT policies: the packet escapes the drop and can reach a later accept (the ponytail note at :1312 is wrong that it only skips the zone) → emit the exclusion as (nfproto != fam) OR (addr != excl) per exclusion family, or reject mixed-family exclusions in validateHosts; drop the false comment.
unkin-agent added 1 commit 2026-10-09 22:54:16 +11:00
Guard zone host exclusions with the address family
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
799c7f3524
Author
Member

No findings.

No findings.
unkin-agent added 1 commit 2026-10-09 23:12:40 +11:00
Merge remote-tracking branch 'origin/main' into benvin/hosts-zones
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
0b68110220
# Conflicts:
#	internal/nftables/compiler.go
#	internal/nftables/compiler_test.go
Author
Member
  • internal/nftables/compiler.go:958 — intraZoneSkip drops every same-interface pair, but hosts entries with routeback (config.HostOptions.RouteBack, set by shorewall convert) are never read by the compiler, so two host groups of one zone on one interface get no intra accept/zone zone policy even with routeback; shorewall emits them → skip the pair only when neither host has Options.RouteBack (and the interface has no routeback), carry the flag on zoneMatch
  • internal/nftables/compiler_test.go:3607 — no same-interface hosts case (with and without host routeback) → add one
- internal/nftables/compiler.go:958 — intraZoneSkip drops every same-interface pair, but hosts entries with `routeback` (config.HostOptions.RouteBack, set by shorewall convert) are never read by the compiler, so two host groups of one zone on one interface get no intra accept/`zone zone` policy even with routeback; shorewall emits them → skip the pair only when neither host has Options.RouteBack (and the interface has no routeback), carry the flag on zoneMatch - internal/nftables/compiler_test.go:3607 — no same-interface hosts case (with and without host routeback) → add one
unkin-agent added 1 commit 2026-10-09 23:15:51 +11:00
Honour hosts routeback for same-interface intra-zone pairs
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
3174eabd94
Author
Member

No findings.

No findings.
benvin merged commit b8ad59b053 into main 2026-10-09 23:28:55 +11:00
benvin deleted branch benvin/hosts-zones 2026-10-09 23:28:55 +11:00
Sign in to join this conversation.