Match any listed port or protocol in a rule #15
Reference in New Issue
Block a user
Delete Branch "benvin/multiport-multiproto"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Rules with several ports or a comma protocol list (
80,443,tcp,udp) never match: each port becomes an AND-ed compare in one rule, andtcp,udpparses to l4proto 0. Shorewalllow:highranges also fail to parse.l4Matches, used by filter, DNAT, SNAT and conntrack rules:range separators:ranges, per-proto reject, expansion counts and errorstcp,or,udp) yields a rule with no proto match but with port compares, i.e. matches any protocol (accept fails open) → skip empty elements or return an errorratelimit: 10/son ports 80,443 or tcp,udp becomes 10/s per expansion (N independent limiters) → share one limiter across the expansion (e.g. a named limit/meter) or reject RateLimit/ConnLimit combined with a listtcp,udpreject must give TCP RST for tcp and icmpx unreach for udp) → add one asserting the Reject type per expansionrule:0x N) and rely on computeDiff grouping by tag with positional compare → add a test that computeDiff(state, state) is empty for a multi-expansion ruletcp,udpp,tpc) compiles to l4proto 0 silently, the same failure this PR fixes fortcp,udp→ make l4Matches validate each element (known name or 0-255 number) and error otherwise.icmp,tcpwith dport80, the icmp branch treats 80 as an ICMP type and tcp as a port, so one list silently yields two unrelated matches → reject port lists that combine ICMP and non-ICMP protos.computeDiff(state, state)compares a state with itself and is always empty, so it does not test diff stability of duplicate-tag expanded rules → compile twice and diff the results, and diff against a state with one expanded rule removed to assert a non-empty change set.bogus; the type/code error path (echo-request/abc) and ICMP list expansion (echo-request,echo-reply, a path this PR changed) are untested → add one case each.:range is tested only for dport on filter rules; sport range, SNAT and conntrack:ranges are untested → add a sport1024:2048case and one SNAT or conntrack range case.net.ParseIP(dnatAddr)is now re-parsed inside the per-match loop → hoist it above the loops and return the error before expansion.No findings.
rejectExprscompares the proto string to "tcp", andcompileOneRulenow passes the raw list element (m.proto), soproto: 6with REJECT gets icmp-port-unreach instead of tcp-reset, unliketcp→ compare the resolved number (protoNumber, == IPPROTO_TCP) or pass the byte vial4MatchTestCompile_RejectPerProtoonly covers the namestcp,udp→ add a case with6(and6,17) asserting NFT_REJECT_TCP_RSTNo findings.