Match dest zone oif on output-chain rules and policies #20
Reference in New Issue
Block a user
Delete Branch "benvin/output-oif"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Output-chain rules and policies ignored the dest zone interface, so fw->zone traffic was accepted or dropped on every interface. Zones with no interfaces had the same unscoped-rule problem in every chain.
fw allexpanding over such a zone) still compiles to an oif-less output rule, i.e. an unconditional accept/drop to every interface; the leak this PR fixes remains for those zones (reproduced:fw ips ACCEPTwith ips=ipsec, no iface →policy:0with no oif) → for chain=="output" with a zone-typed dest and no interface, either skip with the existing warning or match on the zone members (hosts daddr/ipsec policy), and add a test for it.TestCompile_OutputPolicyMatchesOif.srcAddr != ""/dstAddr != ""treats a negated match (vpn:!192.0.2.1) as scoping, so an interface-less zone keeps a rule with no iif/oif that matches nearly all traffic (fail-open, same bug the PR fixes) → only keep when the address is non-negated (!strings.HasPrefix(addr, "!")); add a test forvpn:!192.0.2.1being skipped.warnedis set once.No findings.