Match ORIGDEST in DNAT and filter rules #21

Merged
benvin merged 2 commits from benvin/origdest into main 2026-10-03 22:44:38 +10:00
Member

Shorewall ORIGDEST is ignored today, so rules meant for one public address match every address.

  • DNAT/REDIRECT rules match ORIGDEST as daddr in prerouting (lists split, negated lists AND-ed)
  • Input/output filter rules match ORIGDEST as daddr, guarded by nfproto for the inet table
  • Forwarded rules with ORIGDEST fail to compile: post-DNAT daddr would make them dead (needs ct original daddr, google/nftables v0.3.0)
  • ORIGDEST lists mixing IPv4 and IPv6 fail to compile
Shorewall ORIGDEST is ignored today, so rules meant for one public address match every address. - DNAT/REDIRECT rules match ORIGDEST as daddr in prerouting (lists split, negated lists AND-ed) - Input/output filter rules match ORIGDEST as daddr, guarded by nfproto for the inet table - Forwarded rules with ORIGDEST fail to compile: post-DNAT daddr would make them dead (needs ct original daddr, google/nftables v0.3.0) - ORIGDEST lists mixing IPv4 and IPv6 fail to compile
unkin-agent added 1 commit 2026-10-03 22:16:41 +10:00
Match ORIGDEST in DNAT and filter rules
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
34cf6dc9ab
Author
Member
  • internal/nftables/compiler.go:433 — filter rule with ORIGDEST in the forward chain emits daddr after prerouting DNAT, so it can never match and the rule is silently dead (traffic hits default drop) → return an error ("origdest on forward rules needs google/nftables >= v0.3.0 ct direction") for chain == "forward" instead of emitting an unmatchable rule; add a test for it.
  • internal/nftables/compiler_test.go:1862 — no test for a forward-chain ORIGDEST rule or an IPv6 ORIGDEST DNAT/accept rule → add both.
  • nit: internal/nftables/compiler.go:1412 — nfproto is derived from the first address only; a negated list mixing v4 and v6 gets one wrong-family guard → reject mixed-family negated lists with an error.
- internal/nftables/compiler.go:433 — filter rule with ORIGDEST in the forward chain emits `daddr` after prerouting DNAT, so it can never match and the rule is silently dead (traffic hits default drop) → return an error ("origdest on forward rules needs google/nftables >= v0.3.0 ct direction") for chain == "forward" instead of emitting an unmatchable rule; add a test for it. - internal/nftables/compiler_test.go:1862 — no test for a forward-chain ORIGDEST rule or an IPv6 ORIGDEST DNAT/accept rule → add both. - nit: internal/nftables/compiler.go:1412 — nfproto is derived from the first address only; a negated list mixing v4 and v6 gets one wrong-family guard → reject mixed-family negated lists with an error.
unkin-agent added 1 commit 2026-10-03 22:18:51 +10:00
Reject ORIGDEST on forwarded rules and mixed-family lists
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ff5a52b9e2
Author
Member

No findings.

No findings.
benvin merged commit 532bd80a8a into main 2026-10-03 22:44:38 +10:00
benvin deleted branch benvin/origdest 2026-10-03 22:44:38 +10:00
Sign in to join this conversation.