Compile conntrack rules into raw-priority chains #22
Reference in New Issue
Block a user
Delete Branch "benvin/notrack-raw"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Conntrack (NOTRACK/drop/helper) entries were parsed but never compiled, and zone specs could fail open on typos or exclusions.
raw_prerouting/raw_outputchainsNOTRACK - - udp 53loads)all!x,all+,any!x) in conntrack entriesall!zoneexclusions per zone for filter rulesNo findings.
none(valid at validation) gives dstIfaces=[""] with no addr check (theok &&guard skips it), soSOURCE net DEST nonecompiles toiif=eth0 notrack, a widened match → in raw_prerouting resolve dstZone (skip when unknown/none) and apply the unknown-zone skip to dest, not only src.srcSpecfor+!, soSOURCE lan DEST all+!netdrops lan→lan (forward) whileSOURCE all+!net DEST lankeeps it → check whichever spec is the exclusion (+!in srcSpec or dstSpec) per side.none/unknown in prerouting, nor forlan → all+!xsame-zone pairing → add both.all!netfails open: Sourcefw, Destall!netemits an oif-lessraw_outputrule (from the expandedfwdest) that matches egress vianettoo; alsoall!net:addrin raw_prerouting emits duplicate identical rules per dest zone (dest iface is never matched there) → in raw_output a dest zone with no iface (fw) must not produce an unconditional rule when the dest spec is an exclusion; dedupe prerouting pairs.lan→all!net:192.0.2.1andall!net→lan:192.0.2.1both emit lan→lan (iif=eth1 daddr=...) → reuse the src==dst skip (all!xskips,all+/all+!xpairs) in compileConntrack, and add tests for dest-side exclusion and intra-zone.all/any/all+/any+is treated as a named non-fw zone in the chain switch:chain: bothcompiles raw_prerouting only (raw_output silently dropped, so locally-originated traffic is not NOTRACKed/dropped), andchain: outputerrors. Omitted SOURCE gets both chains → normalize all/any(+) to the global case (src.Zone == "") in the switch, and add a test forSource: "all", Chain: both|output.DROP net $FW/NOTRACK net $FWmatch all inbound traffic from net including forwarded → reject fw DEST in prerouting like other non-address dests (or restrict to raw_output/input-equivalent).Specified = truechange in compileDNATRule are unrelated to conntrack → split into separate PRs (dependency bump; DNAT readback fix).No findings.