Honour shorewall INVALID_DISPOSITION and UNTRACKED_DISPOSITION #31
Reference in New Issue
Block a user
Delete Branch "benvin/invalid-disposition"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
tomswall always drops
ct state invalid, but shorewall appliesINVALID_DISPOSITION(default CONTINUE), so migrated configs are stricter than the source and can break asymmetric ECMP/anycast flows.invalid_dispositionanduntracked_dispositionsettings (accept/drop/reject/continue)INVALID_DISPOSITION/UNTRACKED_DISPOSITIONin migrate, defaulting to continue, A_ variants to their base actionif conf == nil { return nil }runs before the new disposition lines, so a dir with no shorewall.conf/shorewall6.conf is migrated with unset dispositions, i.e. invalid DROP, not shorewall's CONTINUE default → setInvalidDisposition/UntrackedDispositionto continue before that early return (or in convertDir) and add a test with no conf file.invalid_disposition: bogusis rejected andcontinueis accepted.No findings.