Create the nftables table in the configured address family #32

Merged
benvin merged 2 commits from benvin/v4-only-family into main 2026-10-04 15:43:07 +11:00
Member

A migrated shorewall (v4) config sets address_family: ip, but the engine always creates an inet table, so its drop/reject policies also hit IPv6 (NDP, ICMPv6, OSPFv3) that shorewall never filtered.

  • create, read, snapshot and flush the table in the configured address family
  • delete an overlapping table of another family (inet vs ip/ip6) on apply and flush
  • snapshot the replaced table when switching family so try/revert restores it
  • reject with icmp/icmpv6 port-unreachable in ip/ip6 tables (icmpx is inet-only)
A migrated shorewall (v4) config sets `address_family: ip`, but the engine always creates an `inet` table, so its drop/reject policies also hit IPv6 (NDP, ICMPv6, OSPFv3) that shorewall never filtered. - create, read, snapshot and flush the table in the configured address family - delete an overlapping table of another family (inet vs ip/ip6) on apply and flush - snapshot the replaced table when switching family so try/revert restores it - reject with icmp/icmpv6 port-unreachable in ip/ip6 tables (icmpx is inet-only)
unkin-agent added 1 commit 2026-10-04 15:36:09 +11:00
Create the nftables table in the configured address family
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
d949fc4772
Author
Member
  • internal/nftables/engine.go:338-352 — Snapshot returns only the configured-family table when it exists and ignores a coexisting overlapping table that apply() will then delete (ip table + leftover inet: revert loses the inet table) → snapshot the overlapping table whenever staleTables() is non-empty, or document/guard the case.
  • nit: internal/nftables/compiler.go:230 — helper L3Proto is hardcoded NFPROTO_INET but is now created in ip/ip6 tables → derive it from the configured family (NFPROTO_IPV4/IPV6) and add a test for an ip-table helper; confirm the kernel accepts an inet l3proto helper object in an ip table.
- internal/nftables/engine.go:338-352 — Snapshot returns only the configured-family table when it exists and ignores a coexisting overlapping table that apply() will then delete (ip table + leftover inet: revert loses the inet table) → snapshot the overlapping table whenever staleTables() is non-empty, or document/guard the case. - nit: internal/nftables/compiler.go:230 — helper L3Proto is hardcoded NFPROTO_INET but is now created in ip/ip6 tables → derive it from the configured family (NFPROTO_IPV4/IPV6) and add a test for an ip-table helper; confirm the kernel accepts an inet l3proto helper object in an ip table.
unkin-agent added 1 commit 2026-10-04 15:41:10 +11:00
Merge remote-tracking branch 'origin/main' into benvin/v4-only-family
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
d6dfeb62b6
# Conflicts:
#	internal/nftables/engine.go
benvin merged commit b8410488d2 into main 2026-10-04 15:43:07 +11:00
benvin deleted branch benvin/v4-only-family 2026-10-04 15:43:07 +11:00
Sign in to join this conversation.