Exclude sub-zone hosts from wildcard parent interfaces #39

Merged
benvin merged 2 commits from benvin/wildcard-subzone-exclusion into main 2026-10-10 01:08:33 +11:00
Member

A parent zone on a wildcard interface (net enp+) only excluded sub-zone hosts on an exactly matching interface, so lan hosts on enp2s0 were treated as net: lxd net ACCEPT accepted lxd→lan traffic and lan sources hit net all DROP instead of lan's policy. Hosts on wildcard-matched interfaces were also rejected by validation.

  • split a wildcard parent match as shorewall does: each sub-zone host interface gets its own entry with the host exclusions, the wildcard entry negates those interface names and keeps every address
  • accept hosts entries on interfaces matched by a wildcard interfaces entry
  • add tests for input/forward/output classification and interface coverage
A parent zone on a wildcard interface (`net enp+`) only excluded sub-zone hosts on an exactly matching interface, so lan hosts on enp2s0 were treated as net: `lxd net ACCEPT` accepted lxd→lan traffic and lan sources hit `net all DROP` instead of lan's policy. Hosts on wildcard-matched interfaces were also rejected by validation. - split a wildcard parent match as shorewall does: each sub-zone host interface gets its own entry with the host exclusions, the wildcard entry negates those interface names and keeps every address - accept hosts entries on interfaces matched by a wildcard interfaces entry - add tests for input/forward/output classification and interface coverage
unkin-agent added 1 commit 2026-10-09 23:35:56 +11:00
Exclude sub-zone hosts from wildcard parent interfaces
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
190ff72643
Author
Member
  • internal/nftables/compiler.go:1358 — blocking: excluding sub-zone host addresses from the wildcard parent on every overlapping iface leaves that range unzoned when it arrives on another iface the pattern matches (e.g. 192.0.2.5 on enp3s0 is neither net nor lan). Shorewall classes it as net. Policies expand all to concrete zones, so nothing matches it and it hits the chain default. Input/forward default drop (net rules/policies silently stop applying), but the output chain default is ACCEPT, so fw net DROP/REJECT is bypassed for fw → 192.0.2.5 via enp3s0 (reproduced: oif=enp ip4 !daddr=192.0.2.0/24 is the only fw→net match). The PR body "stricter" is wrong for output → scope the exclusion to the sub-zone host own interface (iif=enp2s0 saddr before the parent, parent unexcluded elsewhere), or emit a parent fallback match for the excluded addrs on ifaces other than h.Interface.
  • internal/nftables/compiler_test.go:3666 — no test for excluded range arriving on a different wildcard-matched iface (enp3s0), nor for the output chain → add a test asserting that traffic still classifies as net (and fw→net policy applies).
- internal/nftables/compiler.go:1358 — blocking: excluding sub-zone host addresses from the wildcard parent on every overlapping iface leaves that range unzoned when it arrives on another iface the pattern matches (e.g. 192.0.2.5 on enp3s0 is neither net nor lan). Shorewall classes it as net. Policies expand `all` to concrete zones, so nothing matches it and it hits the chain default. Input/forward default drop (net rules/policies silently stop applying), but the output chain default is ACCEPT, so `fw net DROP/REJECT` is bypassed for fw → 192.0.2.5 via enp3s0 (reproduced: `oif=enp ip4 !daddr=192.0.2.0/24` is the only fw→net match). The PR body "stricter" is wrong for output → scope the exclusion to the sub-zone host own interface (`iif=enp2s0 saddr` before the parent, parent unexcluded elsewhere), or emit a parent fallback match for the excluded addrs on ifaces other than h.Interface. - internal/nftables/compiler_test.go:3666 — no test for excluded range arriving on a different wildcard-matched iface (enp3s0), nor for the output chain → add a test asserting that traffic still classifies as net (and fw→net policy applies).
unkin-agent added 1 commit 2026-10-09 23:41:43 +11:00
Carve sub-zone host interfaces out of wildcard parent matches
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
460eb20db5
Author
Member

No findings.

No findings.
benvin merged commit 9aee3ad7eb into main 2026-10-10 01:08:33 +11:00
benvin deleted branch benvin/wildcard-subzone-exclusion 2026-10-10 01:08:33 +11:00
Sign in to join this conversation.