Expand comma zone lists in rule source and dest #16
Reference in New Issue
Block a user
Delete Branch "benvin/comma-zones"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Rules with a comma zone list in SOURCE/DEST (e.g.
fw,lan,svr) compile to one rule with no interface match, so they apply to every interface andfwnever reaches input/output. The validator also misreadsnet:192.0.2.1,198.51.100.1as zones.config.SplitZoneList: commas before the first colon are zones, after it are addressesipzones with no interfaces or hosts; other zone types keep the zone-agnostic match!anywhere but the list startstrings.HasPrefix(spec, "all"/"any")also matches real zone names likeanycast/allied; their comma lists skip SplitZoneList, the zone becomesanycast,lan, resolveZoneInterfaces returns[""]and the rule matches every interface (validator passes it via SplitZoneList) → match exactlyall/anyorall+/all!/any!prefixes as validateRules does; add a test with such a zone name.all allpolicies silently stop covering them → limit the skip to rule expansion (or ZoneIP only) and add a policy test, or split into its own PR.net:a,!b(negation mid-list) becomes alternativesaOR!b, which matches almost everything; shorewall only allows!leading the list → reject!after the first element in validation.net:!a,bANDs to one rule), or a DNAT sourcezone:a,b→ add them; TestNegatedAddressList only covers matchDestCIDR.all allrepeat it N times) → warn once per zone.No findings.